Description
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Title Uncontrolled Memory Allocation in CODESYS Gateway Client
First Time appeared Codesys
Codesys codesys Development System 3
Codesys codesys Edge Gateway For Linux
Codesys codesys Edge Gateway For Windows
Codesys codesys Gateway
Codesys codesys Hmi Sl
Codesys codesys Opc Da Server Sl
Codesys codesys Plchandler
Codesys codesys Runtime Toolkit
Weaknesses CWE-770
CPEs cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*
Vendors & Products Codesys
Codesys codesys Development System 3
Codesys codesys Edge Gateway For Linux
Codesys codesys Edge Gateway For Windows
Codesys codesys Gateway
Codesys codesys Hmi Sl
Codesys codesys Opc Da Server Sl
Codesys codesys Plchandler
Codesys codesys Runtime Toolkit
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Codesys Codesys Development System 3 Codesys Edge Gateway For Linux Codesys Edge Gateway For Windows Codesys Gateway Codesys Hmi Sl Codesys Opc Da Server Sl Codesys Plchandler Codesys Runtime Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-30T15:28:07.834Z

Reserved: 2026-08-20T06:57:08.465Z

Link: CVE-2026-76992

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T11:16:47.283

Modified: 2026-09-30T16:18:58.660

Link: CVE-2026-76992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T14:00:07Z

Weaknesses