Integer Overflow and Memory Allocation Issues in Apache PLC4X by Apache
CVE-2026-102510
8.7HIGH
What is CVE-2026-102510?
In the Go implementation of Apache PLC4X (PLC4Go), several vulnerabilities allow attackers to exploit integer overflow issues, failing to adequately validate array indexes and manage memory allocation. This can result in denial of service by crashing or exhausting the client application’s memory. Critical defects include unbounded buffer allocation based on claimed data sizes, improper handling of response lengths, and a lack of limits on recursive protocol parsing. The vulnerability impacts versions 0.11.0 through 0.13.1, making it vital for users to upgrade to version 1.0.0 for resolution.
Affected Version(s)
Apache PLC4X 0.11.0 < 1.0.0
Apache PLC4X 1.0.0