Memory Allocation Vulnerability in Apache PLC4X by Apache
CVE-2026-102509

8.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102509?

The vulnerability in Apache PLC4X allows an attacker to exploit memory allocation issues within the Java implementation, leading to denial of service conditions. This occurs through over-allocation of memory when processing length-prefixed byte strings or array fields in generated protocol parsers, particularly in the OPC UA driver. The flaws are triggered before authentication, undermining trust configurations, and can easily lead to memory exhaustion. Users are advised to update to version 1.0.0 to mitigate these risks.

Affected Version(s)

Apache PLC4X 0.10.0 < 1.0.0

Apache PLC4X 0.10.0 < 1.0.0

Apache PLC4X 1.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhinav Agarwal
.