CVE-2026-102510: Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Apache PLC4X Go bindings before 1.0.0 allow remote denial of service via unbounded allocation on wire-controlled lengths.
Christofer Dutz disclosed CVE-2026-102510 in Apache PLC4X's Go implementation (PLC4Go). Versions 0.11.0 before 1.0.0 are affected, while 1.0.0 is unaffected. Integer overflow, improper array-index validation, uncontrolled recursion, and excessive memory allocation let a malicious device or network attacker cause a high availability impact. CVSS 4.0 is 8.7 (network, no privileges, no user interaction); exploitation is not reported.
49