CVE-2026-76992

Summary

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.

Affected Software

VendorProductVersion RangeStatus
CODESYSDevelopment System 33.0.0.0 < 3.5.22.40affected
CODESYSGateway3.0.0.0 < 3.5.22.40affected
CODESYSEdge Gateway for Windows3.0.0.0 < 3.5.22.40affected
CODESYSHMI (SL)3.0.0.0 < 3.5.22.40affected
CODESYSOPC DA Server SL3.0.0.0 < 3.5.22.40affected
CODESYSPLCHandler3.0.0.0 < 3.5.22.40affected
CODESYSRuntime Toolkit3.0.0.0 < 3.5.22.40affected
CODESYSEdge Gateway for Linux3.15.0.0 < 4.23.0.0affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References