Improper Source Verification in Apache PLC4X by Apache
CVE-2026-102511
What is CVE-2026-102511?
The vulnerability in the Go implementation of Apache PLC4X (PLC4Go) stems from improper verification of the source address during ADS discovery. This allows an attacker to redirect connections to an arbitrary address. An attacker who sends a crafted UDP datagram can manipulate discovery results, enabling spoofed responses that direct legitimate applications to untrusted or malicious hosts. Furthermore, malformed datagrams can disrupt legitimate discovery listeners, crashing them or causing resource exhaustion, thereby hampering device discovery or overwhelming system resources. Users are advised to upgrade to version 1.0.0 or later for resolution, which reinforces security by ensuring the connection address aligns with the datagram's source.
Affected Version(s)
Apache PLC4X 0.11.0 < 1.0.0
Apache PLC4X 0.10.0 < 1.0.0
Apache PLC4X 0.10.0 < 1.0.0