PT-2026-103083 · Apache · Apache Plc4X

CVE-2026-102510

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache PLC4X versions 0.11.0 through 0.13.1
Description The Go implementation of Apache PLC4X (PLC4Go) contains multiple flaws including integer overflow, improper validation of array indices, uncontrolled recursion, and memory allocation with excessive size values. These issues allow a malicious device or an attacker capable of injecting network traffic to cause a denial of service by crashing the client application or exhausting its memory. Specifically, generated parsers pre-allocate arrays based on element counts claimed on the wire, and transport read helpers allocate buffers without an upper bound. Additionally, ADS and KNXnet/IP response handling fails to check data length before indexing, leading to a panic. ADS and EIP frame-length handling may accept or wrap to a length of zero, disrupting message framing. Furthermore, recursive protocol types are parsed without a nesting-depth limit. Length and position arithmetic in generated serializers using 16-bit integers can cause the length field to wrap when payloads exceed 8 KB, potentially leading the receiving device to interpret the remainder of the payload as independent protocol messages.
Recommendations Upgrade to version 1.0.0.

Fix

Uncontrolled Recursion

Integer Overflow

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102510

Affected Products

Apache Plc4X