CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Apache PLC4X Java OPC UA driver and SPI parser before 1.0.0 allow pre-authentication resource exhaustion.
Christofer Dutz disclosed CVE-2026-102509 in Apache PLC4X's Java implementation (PLC4J). Versions 0.10.0 before 1.0.0 are affected, and 1.0.0 is unaffected. Excessive memory allocation, allocation without limits, and uncontrolled recursion in the OPC UA driver and Java SPI parser allow pre-authentication denial of service. CVSS 4.0 is 8.7 with network access and high availability impact only; active exploitation is not reported.
- CVE-2026-102509 is rated CVSS 4.0 8.7, availability impact only.
- PLC4J 0.10.0 before 1.0.0 is vulnerable; 1.0.0 is unaffected.
- Flaws are in the OPC UA driver and Java SPI parser.
- The issue is pre-authentication resource exhaustion; no exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-1025098.7—Pre-Authentication Memory and Stack Exhaustion DoS in Apache PLC4X (PLC4J)published · Apache PLC4X (PLC4J, Java implementation)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102509 | Pre-Authentication Memory and Stack Exhaustion DoS in Apache PLC4X (PLC4J) Apache PLC4X's Java implementation (PLC4J) from 0.10.0 through 0.13.1 contains five related resource-exhaustion defects — allocating length-prefixed byte strings from claimed wire lengths before validation, pre-allocating parser lists and collections from attacker-supplied element counts, accumulating OPC UA message chunks without enforcing negotiated limits, and parsing recursive types without a nesting-depth cap. A malicious or impersonated PLC device or OPC UA server can trigger multi-gigabyte allocations or stack exhaustion by sending a single forged length/count field or oversized chunked message, crashing the connecting client application — the impact is denial of service only (CVSS 4.0 8.7, availability-only). Critically, in the OPC UA driver the offending data is parsed while the secure channel and session are still being established, before the server's identity is bound, so configuring a trusted server does not stop an attacker who can impersonate one. Any Java application embedding PLC4X 0.10.0–0.13.1 is affected: the generated-parser defect is shared by all PLC4J drivers, with the OPC UA driver the verified pre-authentication path (chunk-accumulation defect 0.12.0–0.13.1). No public PoC or known exploitation exists and the CVE is not in CISA's KEV catalog; the fix shipped in version 1.0.0, with the analogous Go implementation flaw tracked separately as CVE-2026-102510. |
Posted by Christofer Dutz on Sep 30 Severity: CVSS 4.0: 8.7 (high) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected versions: - Apache PLC4X 0.10.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected - Apache PLC4X 0.10.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected Description: Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a...
This source does not provide full text. Read it at seclists.org.