Apache PLC4X before 1.0.0 has three high-severity flaws
Apache PLC4X before 1.0.0 has two resource-exhaustion bugs and an ADS discovery spoofing flaw; 1.0.0 is unaffected.
Three oss-security notes published on 2026-09-30 describe high-severity flaws in Apache PLC4X before 1.0.0, all fixed in 1.0.0 and with no reported active exploitation. CVE-2026-102509, disclosed by Christofer Dutz, is pre-authentication resource exhaustion in the Java OPC UA driver and SPI parser (PLC4J 0.10.0 before 1.0.0), scored CVSS 4.0 8.7 with availability impact only. CVE-2026-102510, also disclosed by Dutz, lets a malicious device or network attacker force unbounded allocation and related framing failures in the Go bindings (PLC4Go 0.11.0 before 1.0.0), likewise CVSS 4.0 8.7 and availability-only. CVE-2026-102511, which the third note attributes to Apache rather than naming Dutz, scores CVSS 4.0 8.5: ADS discovery accepts spoofed responses and uses them to set the connection target on the 0.10.0 and 0.11.0 lines before 1.0.0. Affected ranges therefore differ by component, while all three notes agree that 1.0.0 is unaffected.
- CVE-2026-102509 (CVSS 4.0 8.7, availability only) affects Apache PLC4X Java (PLC4J) 0.10.0 before 1.0.0: pre-authentication resource exhaustion in the OPC UA driver and Java SPI parser via excessive allocation, unbounded allocation, and…
- CVE-2026-102510 (CVSS 4.0 8.7, network, no privileges, no user interaction, availability only) affects PLC4Go 0.11.0 before 1.0.0: unbounded allocation and framing failures on wire-controlled lengths, including integer overflow, improper…
- CVE-2026-102511 (CVSS 4.0 8.5) affects Apache PLC4X 0.10.0 and 0.11.0 lines before 1.0.0: ADS discovery accepts spoofed responses and derives the connection target from them (improper source verification).
- Apache PLC4X 1.0.0 is unaffected for all three issues; oss-security notes do not report in-the-wild exploitation.
- Christofer Dutz is named as disclosing CVE-2026-102509 and CVE-2026-102510; the ADS note attributes CVE-2026-102511 to Apache.
Coverage timelineoldest first · each row is one article
- · 8d agoCVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
oss-security· 49
Apache PLC4X Java OPC UA driver and SPI parser before 1.0.0 allow pre-authentication resource exhaustion.
- · 8d agoCVE-2026-102510: Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
oss-security· 49
Apache PLC4X Go bindings before 1.0.0 allow remote denial of service via unbounded allocation on wire-controlled lengths.
- · 8d ago
Vulnerabilities in this storyAll →
- CVE-2026-1025098.7—Pre-Authentication Memory and Stack Exhaustion DoS in Apache PLC4X (PLC4J)published · Apache PLC4X (PLC4J, Java implementation)
- CVE-2026-1025108.7—Unbounded Allocation and Framing Flaws in Apache PLC4X PLC4Go (pre-1.0.0)published · Apache Software Foundation Apache PLC4X (PLC4Go, Go module github.com/apache/plc4x/plc4go)