Severity: 
    CVSS 4.0: 8.7 (high) 
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected versions:

- Apache PLC4X 0.10.0 before 1.0.0
- Apache PLC4X 1.0.0 unaffected
- Apache PLC4X 0.10.0 before 1.0.0
- Apache PLC4X 1.0.0 unaffected

Description:

Memory Allocation with Excessive Size Value, Allocation of Resources Without 
Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X 
(PLC4J) allow a malicious or impersonated device to exhaust the memory or stack 
of the client application, causing a denial of service.

In the OPC UA driver these defects are reachable before authentication: the 
offending data is parsed while the secure channel and session are being 
established, before the server's identity has been bound to it. Configuring a 
trusted server therefore does not prevent exploitation by an attacker who can 
impersonate it.

The individual defects are:
- Length-prefixed byte strings are allocated at the size claimed on the wire 
before the length is checked against the data actually received (0.10.0 through 
0.13.1).
- Array fields in generated protocol parsers pre-allocate a list with the 
element count claimed on the wire, allowing a single count field to trigger a 
multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC 
UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).
- The OPC UA driver accumulates message chunks without enforcing the negotiated 
maximum chunk count and message size (0.12.0 through 0.13.1).
- The OPC UA driver pre-allocates collections using element counts received 
from the server (0.10.0 through 0.13.1).
- Recursive protocol types are parsed without a nesting-depth limit. The same 
defect in the Go implementation is covered by  CVE-2026-102510 
https://cveprocess.apache.org/cve5/CVE-2026-102510 .

This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.

Credit:

Abhinav Agarwal (finder)

References:

https://plc4x.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-102509

Timeline:

2026-07-09: reported to the Apache Security Team
2026-07-10: reported issues fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)
2026-09-07: Apache PLC4X 1.0.0 released with the fixes

Reply via email to