org.apache.plc4x:plc4j-driver-opcua vulnerabilities
CVEs whose affected-version data names the org.apache.plc4x:plc4j-driver-opcua package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-102509High· 8.7Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of…
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of…
▾ TwilightApache Software Foundation · org.apache.plc4x:plc4j-spivia NVD
CVE-2026-102508Critical· 9.2Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to …
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to …
▾ MidnightApache Software Foundation · org.apache.plc4x:plc4j-driver-opcuavia NVD