A notice published on September 30, 2026 reports pre-authentication resource exhaustion in PLC4J, Apache PLC4X’s Java implementation. Version 1.0.0 is listed as unaffected.
A security notice published on September 30, 2026 describes a flaw in PLC4J, Apache PLC4X’s Java implementation. According to the text, excessive memory allocation, unbounded resource allocation, and uncontrolled recursion can cause resource exhaustion without authentication. The reported severity is CVSS 4.0 8.7, rated high. The stated vector is network access, with no privileges or user interaction, and a high availability impact.
The notice lists Apache PLC4X versions 0.10.0 before 1.0.0 as affected and identifies 1.0.0 as unaffected. Consult the original notice in the oss-sec feed to check its scope and track corrections; compare the version in use against the published list and verify details with the Apache PLC4X project. The available text is an automatic translation and its description ends incomplete, so it does not support conclusions about further technical details.