Integer Overflow and Memory Allocation Issues in Apache PLC4X by Apache
CVE-2026-102510

8.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102510?

In the Go implementation of Apache PLC4X (PLC4Go), several vulnerabilities allow attackers to exploit integer overflow issues, failing to adequately validate array indexes and manage memory allocation. This can result in denial of service by crashing or exhausting the client application’s memory. Critical defects include unbounded buffer allocation based on claimed data sizes, improper handling of response lengths, and a lack of limits on recursive protocol parsing. The vulnerability impacts versions 0.11.0 through 0.13.1, making it vital for users to upgrade to version 1.0.0 for resolution.

Affected Version(s)

Apache PLC4X 0.11.0 < 1.0.0

Apache PLC4X 1.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.