Apache PLC4X: denial of service
High8.7CVE-2026-102509 · Published Sep 30, 2026
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service. In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it. The individual defects are: - Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1). - Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1). - The OPC UA driver accumulates message chunks without enforcing the negotiated maximum...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache PLC4X Product | >= 0.10.0, < 1.0.0 | 1.0.0 |
| >= 0.10.0, < 1.0.0 | 1.0.0 |
Details and references
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service. In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it. The individual defects are: - Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1). - Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1). - The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1). - The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1). - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 . This issue affects Apache PLC4X: from 0.10.0 before 1.0.0. Users are recommended to upgrade to version 1.0.0, which fixes the issue.
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Apache WSS4J: integer overflow | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: insufficient authenticity check | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: expression injection | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass | Critical9.8 | 4.0.2+2 more |