CVE-2026-76992
Received Received - Intake

Memory Exhaustion in CODESYS Gateway Client

Vulnerability report for CVE-2026-76992, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CERT VDE

Description

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
codesys development_system 3.5.22.40
codesys edge_gateway_for_linux 4.23.0.0
codesys edge_gateway_for_windows *
codesys gateway *
codesys hmi *
codesys opc_da_server_sl *
codesys plchandler *
codesys runtime_toolkit *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the CODESYS Gateway Client involves improper memory allocation. When the client receives a gateway response containing a size field, it allocates memory based on that value without checking for reasonable limits. An attacker controlling a malicious gateway can exploit this to force excessive memory consumption, causing a denial-of-service and complete loss of availability.

Detection Guidance

Monitor network traffic for connections to CODESYS Gateway services. Check for unusually high memory usage in CODESYS-related processes. Inspect logs for failed memory allocation errors in affected products.

Impact Analysis

If you use affected CODESYS products connected to a gateway, an attacker could exploit this flaw to crash your system by consuming all available memory. This would disrupt operations relying on CODESYS products, such as PLC communication, development, or runtime environments.

Compliance Impact

This vulnerability causes a denial-of-service condition due to excessive memory consumption, leading to total loss of availability. While not directly violating GDPR or HIPAA, such disruptions could impact compliance by failing to maintain availability of critical systems required by these regulations.

Mitigation Strategies

Update affected CODESYS products to the latest versions (3.5.22.40 or 4.23.0.0). Restrict network access to CODESYS Gateway services. Monitor memory usage for signs of excessive consumption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76992. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart