CVE-2026-102509
Received Received - Intake

Memory Exhaustion in Apache PLC4X Java Implementation

Vulnerability report for CVE-2026-102509, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service. In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it. The individual defects are: - Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1). - Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1). - The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1). - The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1). - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 . This issue affects Apache PLC4X: from 0.10.0 before 1.0.0. Users are recommended to upgrade to version 1.0.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apache plc4x 1.0.0
apache plc4x From 0.10.0 (inc) to 1.0.0 (exc)
apache plc4x From 0.10.0 (inc) to 0.13.1 (inc)
apache plc4x From 0.12.0 (inc) to 0.13.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves memory allocation issues in Apache PLC4X's Java implementation (PLC4J). A malicious or impersonated device can exploit flaws in parsing data to exhaust memory or stack resources in the client application, causing a denial of service. The OPC UA driver is particularly vulnerable before authentication, allowing attacks even if a trusted server is configured.

Detection Guidance

This vulnerability involves memory exhaustion or stack overflow in Apache PLC4X (PLC4J) due to improper handling of data sizes and recursion. Detection requires monitoring for abnormal memory usage or crashes in applications using affected versions (0.10.0 to 0.13.1). Check logs for OPC UA driver errors or excessive memory consumption during network communication.

Impact Analysis

An attacker could crash your client application by sending maliciously crafted data, leading to service disruption. This is possible even if you configure trusted servers, as the OPC UA driver is vulnerable before authentication. The impact includes system downtime and potential loss of control over industrial processes.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt system availability. Memory exhaustion or stack overflows may cause client applications to crash, leading to service unavailability which could violate availability requirements in these regulations.

Mitigation Strategies

Upgrade Apache PLC4X to version 1.0.0 or later to fix the vulnerability. The affected versions are from 0.10.0 through 0.13.1.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102509. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart