CVE-2026-76992: Uncontrolled Memory Allocation in CODESYS Gateway Client
Published Sep 30, 2026
·Updated
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
Affected Software
1 affected component
CODESYS Gateway Client
Event History
Sep 30, 2026
CVE Published
via MITRE·11:07 AM
Data Sourced
via MITRE·11:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What attacker position is required to exploit this issue?
An unauthenticated remote attacker must control a malicious gateway that provides crafted gateway responses to the CODESYS Gateway Client. No user interaction or prior privileges are required.
2
What is the operational impact of successful exploitation?
The attacker can cause the client to allocate excessive memory, resulting in a denial-of-service condition. The stated impact is total loss of availability.