Improper Source Verification in Apache PLC4X by Apache
CVE-2026-102511

8.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-102511?

The vulnerability in the Go implementation of Apache PLC4X (PLC4Go) stems from improper verification of the source address during ADS discovery. This allows an attacker to redirect connections to an arbitrary address. An attacker who sends a crafted UDP datagram can manipulate discovery results, enabling spoofed responses that direct legitimate applications to untrusted or malicious hosts. Furthermore, malformed datagrams can disrupt legitimate discovery listeners, crashing them or causing resource exhaustion, thereby hampering device discovery or overwhelming system resources. Users are advised to upgrade to version 1.0.0 or later for resolution, which reinforces security by ensuring the connection address aligns with the datagram's source.

Affected Version(s)

Apache PLC4X 0.11.0 < 1.0.0

Apache PLC4X 0.10.0 < 1.0.0

Apache PLC4X 0.10.0 < 1.0.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.