Published on September 30, 2026, in the oss-sec feed, the advisory concerns Apache PLC4X’s Go implementation, known as PLC4Go. The flaw may enable resource exhaustion and denial of service when a malicious device or injected network traffic exploits network-controlled lengths.
The text cites integer overflow, improper array-index validation, uncontrolled recursion, and excessive memory allocation. The CVSS 4.0 assessment is 8.7, rated high; its vector indicates network access, low complexity, no privileges or user interaction, and high availability impact.
According to the advisory, Apache PLC4X 0.11.0 versions before 1.0.0 are affected; version 1.0.0 is not. Check your dependency inventory against the original advisory in the oss-sec feed. Verify the version and assessment at the source before deciding on an update; the available excerpt does not specify other fixed versions.
If using AI to summarize or apply the advisory, submit only necessary excerpts and remove names, contact details, credentials, and internal network details. Validate technical conclusions against the original advisory and your organization’s vulnerability-management process.