VYPR

plc4go

by Apache

CVEs (2)

  • CVE-2026-102510HigSep 30, 2026
    risk 0.50cvss —epss —

    Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory…

  • CVE-2026-102511HigSep 30, 2026
    risk 0.48cvss —epss —

    Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address.…