Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102509— Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser

Quick assessment

Affected
Apache Software Foundation Apache PLC4X
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache PLC4X 的 Java 实现(PLC4J)中存在“使用过大尺寸值进行内存分配”、“无限制地分配资源”以及“不受控制的递归”等缺陷,允许恶意设备或伪装成合法设备的攻击者耗尽客户端应用的内存或栈空间,从而导致拒绝服务(DoS)攻击。 在 OPC UA 驱动中,这些缺陷可在身份验证之前被触发:相关数据是在建立安全通道和会话过程中、且服务器身份尚未与其绑定时即被解析的。因此,即使配置了受信任的服务器,也无法防止能够伪装该服务器的攻击者利用此漏洞。 具体缺陷如下: 在长度前缀字节串中,系统先根据网络传输中声明

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102509

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Source: CVE Program / CVE List V5
Vulnerability Description
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service. In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can impersonate it. The individual defects are: - Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1). - Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1). - The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1). - The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1). - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 . This issue affects Apache PLC4X: from 0.10.0 before 1.0.0. Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache PLC4X 0.10.0 ~ 1.0.0 -
Apache Software Foundation Apache PLC4X 0.10.0 ~ 1.0.0 -

II. Public POCs for CVE-2026-102509

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102509

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-102509 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-30 · 19 CVEs total

CVE-2026-102508 9.2 CRITICAL Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD: Asynchronous authentication can bypass signature verification
CVE-2026-102510 8.7 HIGH Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len
CVE-2026-102511 8.5 HIGH Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp
CVE-2026-93994 8.1 HIGH Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002 7.5 HIGH Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce

IV. Related Vulnerabilities

V. Comments for CVE-2026-102509

No comments yet


Leave a comment