---
id: CVE-2026-76992
title: >-
  The CODESYS Gateway Client allocates memory based on a size field in a gateway
  response without enforcing an appropriate upper limit
summary: >-
  The CODESYS Gateway Client allocates memory based on a size field in a gateway
  response without enforcing an appropriate upper limit. An unauthenticated
  remote attacker controlling a malicious gateway can exploit this behavior to
  trigger…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: CODESYS
product: Development System 3
affected:
  - development_system_3 >= 3.0.0.0 < 3.5.22.40
  - Gateway >= 3.0.0.0 < 3.5.22.40
  - edge_gateway_for_windows >= 3.0.0.0 < 3.5.22.40
  - hmi_sl >= 3.0.0.0 < 3.5.22.40
  - opc_da_server_sl >= 3.0.0.0 < 3.5.22.40
  - PLCHandler >= 3.0.0.0 < 3.5.22.40
  - runtime_toolkit >= 3.0.0.0 < 3.5.22.40
  - edge_gateway_for_linux >= 3.15.0.0 < 4.23.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T11:16:47.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76992'
references:
  - url: 'https://www.certvde.com/en/advisories/VDE-2026-094/'
    label: info@cert.vde.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T12:02:58.583Z'
---

## Overview

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
