CVE-2026-102510
Received Received - Intake

Memory Exhaustion in Apache PLC4X PLC4Go

Vulnerability report for CVE-2026-102510, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a denial of service. The individual defects are: - Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1). - Transport read helpers allocate buffers of the size claimed on the wire without an upper bound. - ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic. - ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing. - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 . Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as additional, independent protocol messages. This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apache plc4x to 1.0.0 (exc)
apache plc4x 1.0.0
apache plc4go *
apache plc4x From 0.13.0 (inc) to 0.13.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache PLC4X (PLC4Go) involves multiple flaws like integer overflow, improper array index validation, uncontrolled recursion, and excessive memory allocation. Attackers can exploit these to crash client applications or cause denial of service by sending malicious network traffic or manipulating payload sizes.

Detection Guidance

This vulnerability involves crashes or memory exhaustion due to improper handling of network traffic in Apache PLC4X (PLC4Go). Detection requires monitoring for unexpected crashes, high memory usage, or network anomalies in applications using affected versions (0.11.0 to 0.13.1). Check logs for panics or out-of-memory errors. Validate if your system uses PLC4Go versions before 1.0.0.

Impact Analysis

If you use affected versions of Apache PLC4X (0.11.0 to 0.13.1), an attacker could crash your application or exhaust its memory, leading to service disruption. This is especially critical if your system processes untrusted network input or forwards large payloads.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt system availability. Exhausting memory or crashing client applications may lead to unauthorized data access or processing interruptions, violating availability requirements in these regulations.

Mitigation Strategies

Upgrade Apache PLC4X to version 1.0.0 or later to address the identified vulnerabilities. Ensure all components using PLC4Go are updated to prevent crashes or memory exhaustion from malicious network traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102510. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart