CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Apache PLC4X Java OPC UA driver and SPI parser before 1.0.0 allow pre-authentication resource exhaustion.
Christofer Dutz disclosed CVE-2026-102509 in Apache PLC4X's Java implementation (PLC4J). Versions 0.10.0 before 1.0.0 are affected, and 1.0.0 is unaffected. Excessive memory allocation, allocation without limits, and uncontrolled recursion in the OPC UA driver and Java SPI parser allow pre-authentication denial of service. CVSS 4.0 is 8.7 with network access and high availability impact only; active exploitation is not reported.