CVE-2026-102509

Summary

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.

In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it.

The individual defects are:

  • Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).
  • Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).
  • The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).
  • The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).
  • Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .

This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache PLC4X0.10.0 < 1.0.0affected
Apache Software FoundationApache PLC4X1.0.0unaffected
Apache Software FoundationApache PLC4X0.10.0 < 1.0.0affected
Apache Software FoundationApache PLC4X1.0.0unaffected

Weaknesses

  • CWE-789: CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).
  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).
  • CWE-674: CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045).

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References