Description
Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,
causing a denial of service.

The individual defects are:
- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).
- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.
- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.
- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.
- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .

Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as
additional, independent protocol messages.

This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Go binding (PLC4Go) of Apache PLC4X and involves several improper validation issues: integer overflows in 16‑bit length calculations, unbounded allocation of arrays and buffers based on values supplied on the wire, out‑of‑bounds indexing into received data, and unrestrained recursive parsing of protocol types. These flaws allow an attacker who can inject or influence network traffic to cause the client application to crash or exhaust its memory, resulting in a denial‑of‑service condition. The weaknesses correspond to CWE‑129, CWE‑190, CWE‑674 and CWE‑789.

Affected Systems

Affected components are the Apache PLC4X project, specifically the Go binding (PLC4Go) consumed as the Go module github.com/apache/plc4x/plc4go. Vulnerable versions span from 0.11.0 up through releases prior to 1.0.0, including the 0.13.0 and 0.13.1 releases. Systems that use older PLC4Go versions and parse PLC traffic from devices such as ADS or KNXnet/IP can be impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS value is not available, suggesting that publicly available exploitation data is lacking but not that the risk is minimal. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is remote, via crafted PLC protocol messages that an attacker can send to a client application that is actively communicating with a PLC or similar device. If an attacker can inject such traffic—either from the same network or by compromising a connected PLC—he can trigger the unbounded allocations or arithmetic overflows, forcing the client to consume excessive memory or crash. There is no evidence that the flaw requires local privileges or access to privileged credentials; the exploit can be performed by any attacker who can deliver the malformed packets to the target client.

Generated by OpenCVE AI on September 30, 2026 at 12:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PLC4Go dependency to version 1.0.0 or later to receive the fix that removes the uncontrolled allocations, adds proper bounds checking, and limits recursion.
  • Audit existing Go module files and the go.mod entries to ensure that all references to plc4go are at least 1.0.0, clean the module cache, and rebuild the binaries.
  • If an immediate upgrade cannot occur, implement network‑level filtering or firewall rules to block anomalous PLC traffic, and modify or wrap PLC4Go parsing functions to enforce a maximum frame size (e.g., 8 KB) and to check array bounds before allocation; also implement a nesting depth counter for recursive protocol parsing to avoid stack exhaustion.

Generated by OpenCVE AI on September 30, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a denial of service. The individual defects are: - Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1). - Transport read helpers allocate buffers of the size claimed on the wire without an upper bound. - ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic. - ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing. - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 . Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as additional, independent protocol messages. This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Title Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Weaknesses CWE-129
CWE-190
CWE-674
CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-30T14:40:31.604Z

Reserved: 2026-09-29T11:41:34.033Z

Link: CVE-2026-102510

cve-icon Vulnrichment

Updated: 2026-09-30T14:40:28.613Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:14.293

Modified: 2026-09-30T16:14:10.347

Link: CVE-2026-102510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-190

    Integer Overflow or Wraparound

  • CWE-674

    Uncontrolled Recursion

  • CWE-789

    Memory Allocation with Excessive Size Value