PT-2026-103082 · Apache · Apache Plc4X
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Apache PLC4X versions 0.10.0 through 0.13.1
Description
Memory allocation with excessive size values, allocation of resources without limits, and uncontrolled recursion in the Java implementation of Apache PLC4X (PLC4J) can allow a malicious or impersonated device to exhaust the memory or stack of the client application, leading to a denial of service. In the OPC UA driver, these issues are reachable before authentication during the establishment of the secure channel and session. Technical details include:
- Length-prefixed byte strings are allocated based on the size claimed on the wire before verifying the actual data received.
- Generated protocol parsers pre-allocate lists based on element counts claimed on the wire, which can trigger multi-gigabyte allocations. This parser is used by all PLC4J drivers, with the OPC UA driver as a verified pre-authentication path.
- The OPC UA driver fails to enforce negotiated maximum chunk counts and message sizes when accumulating message chunks.
- The OPC UA driver pre-allocates collections using element counts received from the server.
- Recursive protocol types are parsed without a nesting-depth limit.
Recommendations
Upgrade to version 1.0.0.
Fix
Allocation of Resources Without Limits
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Plc4X