CVE-2026-102510
Last modified
CVE-2026-102510 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a denial of service. The individual defects are: - Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1). - Transport read helpers allocate buffers of the size claimed on the wire without an upper bound. - ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic. - ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing. - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 . Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers.
Description
Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a denial of service. The individual defects are: - Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1). - Transport read helpers allocate buffers of the size claimed on the wire without an upper bound. - ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic. - ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing. - Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 . Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as additional, independent protocol messages. This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache PLC4X | >= 0.11.0, < 1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102510?
How severe is CVE-2026-102510?
How do I fix CVE-2026-102510?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102504Imager versions before 1.037 for Perl exit the process readi…7.5
- CVE-2026-102505Imager versions before 1.037 for Perl overflow a heap buffer…6.3
- CVE-2026-102507Sliver C2 framework version 1.7.7 and earlier contains an un…5.7
- CVE-2026-102508Improper Verification of Cryptographic Signature and Imprope…9.2
- CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of R…8.7
- CVE-2026-10251A weakness has been identified in itsourcecode Online House …7.3
- CVE-2026-102511Improper Verification of Source of a Communication Channel i…8.5
- CVE-2026-102514Out-of-bounds Write (CWE-787) in the PEA archive extraction …8.4
- CVE-2026-10252A security vulnerability has been detected in itsourcecode O…7.3
- CVE-2026-102521The decoder in `readFromDataView` in lib0 before 0.2.119 can…8.6
- CVE-2026-10253A vulnerability was detected in itsourcecode Online House Re…7.3
- CVE-2026-10254A flaw has been found in SourceCodester Pet Grooming Managem…5.5
Are you affected by CVE-2026-102510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
