Severity: 
    CVSS 4.0: 8.7 (high) 
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected versions:

- Apache PLC4X 0.11.0 before 1.0.0
- Apache PLC4X 1.0.0 unaffected

Description:

Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion 
and Memory Allocation with Excessive Size Value in the Go implementation of 
Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject 
network traffic, to crash or exhaust the memory of the client application,
causing a denial of service.

The individual defects are:
- Generated parsers pre-allocate arrays with the element count claimed on the 
wire (0.13.0 through 0.13.1).
- Transport read helpers allocate buffers of the size claimed on the wire 
without an upper bound.
- ADS and KNXnet/IP response handling indexes into received data without 
checking its length, causing a panic.
- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a 
length of zero, breaking message framing.
- Recursive protocol types are parsed without a nesting-depth limit. The same 
defect in the Java implementation is covered by  CVE-2026-102509 
https://cveprocess.apache.org/cve5/CVE-2026-102509 .

Additionally, length and position arithmetic in generated serializers was 
performed in 16-bit integers. If an application forwards attacker-influenced 
payloads larger than 8 KB, the length field wraps, and the remainder of the 
payload may be interpreted by the receiving device (for example, an ADS PLC) as 
additional, independent protocol messages.

This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed 
as the Go module github.com/apache/plc4x/plc4go; versions refer to the 
corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.

References:

https://plc4x.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-102510

Timeline:

2026-08-11: found during the internal security review
2026-09-07: Apache PLC4X 1.0.0 released with the fixes

Reply via email to