CVE-2026-102509 PUBLISHED

Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser

Assigner: apache
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.

In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it.

The individual defects are: - Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1). - Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1). - The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1). - The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1). - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .

This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Apache Software Foundation
Product Apache PLC4X
Versions Default: unaffected
  • affected from 0.10.0 to 1.0.0 (excl.)
  • Version 1.0.0 is unaffected
Vendor Apache Software Foundation
Product Apache PLC4X
Versions Default: unaffected
  • affected from 0.10.0 to 1.0.0 (excl.)
  • Version 1.0.0 is unaffected

Credits

  • Abhinav Agarwal finder

References

Problem Types

  • CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024). CWE
  • CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3). CWE
  • CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045). CWE