Unbounded Allocation and Framing Flaws in Apache PLC4X PLC4Go (pre-1.0.0)
CVSS 4.0
8.7high
EPSS
—
Published
()
Modified
AI analysis
The Go implementation of Apache PLC4X (PLC4Go) contains multiple parsing and serialization defects — integer overflow, missing array-index validation, uncontrolled recursion, and wire-controlled memory allocation — that let a malicious PLC/device or an attacker who can inject traffic on the industrial protocol connection crash or exhaust the memory of the client application, causing denial of service. Specific triggers include response frames claiming huge element counts or buffer sizes, ADS/KNXnet/IP responses shorter than the offsets indexed into them, ADS and EtherNet/IP frame lengths of zero or values that wrap to zero, and recursively nested protocol types with no depth limit. A separate 16-bit length/position arithmetic bug in generated serializers means that if an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps and the remainder can be interpreted by the receiving device (for example, a Beckhoff ADS PLC) as additional independent protocol messages — a potential integrity risk beyond simple DoS. Affected software is anything embedding the Go module github.com/apache/plc4x/plc4go at versions 0.11.0 through 0.13.x; the fix is version 1.0.0. There is no known public PoC and no indication of exploitation in the wild.
What to do: Upgrade the github.com/apache/plc4x/plc4go dependency to Apache PLC4X 1.0.0 (check go.mod for any 0.11.0–0.13.x pin), and patch the Java implementation as well if you also use it (CVE-2026-102509). Until upgraded, restrict PLC protocol traffic to trusted, segmented OT networks so untrusted devices or traffic injectors cannot reach the client, and audit whether your application forwards attacker-influenced payloads larger than 8 KB, since those can be re-framed into extra messages on the receiving device.
Affected
Apache Software Foundation Apache PLC4X (PLC4Go, Go module github.com/apache/plc4x/plc4go)
>= 0.11.0, < 1.0.0
Apache Software Foundation Apache PLC4X PLC4Go generated parsers (array pre-allocation from wire-claimed element count)
0.13.0 through 0.13.1
Estimated exposure
Description
Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a denial of service. The individual defects are: - Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1). - Transport read helpers allocate buffers of the size claimed on the wire without an upper bound. - ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic. - ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing. - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 . Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as additional, independent protocol messages. This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue.
likely low thousands of embedded deployments at most (hundreds to a few thousand client applications) — PLC4Go is a developer library rather than a shipped product, has no published install or download telemetry like a plugin's active-install count, and Go-based industrial gateway/PLC-client deployments are a narrow population, so this is a…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Apache PLC4X Go bindings before 1.0.0 allow remote denial of service via unbounded allocation on wire-controlled lengths.
Christofer Dutz disclosed CVE-2026-102510 in Apache PLC4X's Go implementation (PLC4Go). Versions 0.11.0 before 1.0.0 are affected, while 1.0.0 is unaffected. Integer overflow, improper array-index validation, uncontrolled recursion, and excessive memory allocation let a malicious device or network attacker cause a high availability impact. CVSS 4.0 is 8.7 (network, no privileges, no user interaction); exploitation is not reported.