CVE-2026-102510: Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Apache PLC4X Go bindings before 1.0.0 allow remote denial of service via unbounded allocation on wire-controlled lengths.
Christofer Dutz disclosed CVE-2026-102510 in Apache PLC4X's Go implementation (PLC4Go). Versions 0.11.0 before 1.0.0 are affected, while 1.0.0 is unaffected. Integer overflow, improper array-index validation, uncontrolled recursion, and excessive memory allocation let a malicious device or network attacker cause a high availability impact. CVSS 4.0 is 8.7 (network, no privileges, no user interaction); exploitation is not reported.
- CVE-2026-102510 scores CVSS 4.0 8.7 with availability-only impact.
- PLC4Go 0.11.0 before 1.0.0 is affected; 1.0.0 is unaffected.
- A malicious device or injected traffic can force excessive allocation.
- No in-the-wild exploitation is mentioned.
Vulnerabilities mentionedAll →
- CVE-2026-1025108.7—Unbounded Allocation and Framing Flaws in Apache PLC4X PLC4Go (pre-1.0.0)published · Apache Software Foundation Apache PLC4X (PLC4Go, Go module github.com/apache/plc4x/plc4go)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102510 | Unbounded Allocation and Framing Flaws in Apache PLC4X PLC4Go (pre-1.0.0) The Go implementation of Apache PLC4X (PLC4Go) contains multiple parsing and serialization defects — integer overflow, missing array-index validation, uncontrolled recursion, and wire-controlled memory allocation — that let a malicious PLC/device or an attacker who can inject traffic on the industrial protocol connection crash or exhaust the memory of the client application, causing denial of service. Specific triggers include response frames claiming huge element counts or buffer sizes, ADS/KNXnet/IP responses shorter than the offsets indexed into them, ADS and EtherNet/IP frame lengths of zero or values that wrap to zero, and recursively nested protocol types with no depth limit. A separate 16-bit length/position arithmetic bug in generated serializers means that if an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps and the remainder can be interpreted by the receiving device (for example, a Beckhoff ADS PLC) as additional independent protocol messages — a potential integrity risk beyond simple DoS. Affected software is anything embedding the Go module github.com/apache/plc4x/plc4go at versions 0.11.0 through 0.13.x; the fix is version 1.0.0. There is no known public PoC and no indication of exploitation in the wild. |
Posted by Christofer Dutz on Sep 30 Severity: CVSS 4.0: 8.7 (high) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected versions: - Apache PLC4X 0.11.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected Description: Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network...
This source does not provide full text. Read it at seclists.org.