CVE-2026-76992 Details
Description
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
A denial-of-service vulnerability has been identified in the CODESYS Gateway Client. This issue arises from uncontrolled memory allocation based on a size field in gateway responses, allowing an unauthenticated remote attacker to cause excessive memory consumption. The vulnerability is present in CODESYS Gateway Clients that connect to malicious gateways, leading to a total loss of availability.
Users can update to version 3.5.22.40 for CODESYS Development System 3, CODESYS Gateway, CODESYS Edge Gateway for Windows, CODESYS HMI (SL), CODESYS OPC DA Server SL, CODESYS PLCHandler, and CODESYS Runtime Toolkit. CODESYS Edge Gateway for Linux users should wait for the release of version 4.23.0.0, expected in Q4 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-094/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CODESYS Gateway Client | >= 3.0.0.0, < 3.5.22.40 |
CPE
Remediation
| |
| CODESYS Development System | All versions |
CPE
Remediation
| |
| CODESYS Edge Gateway | All versions |
CPE
Remediation
| |
| CODESYS Gateway | All versions |
CPE
Remediation
| |
| CODESYS HMI | All versions |
CPE
Remediation
| |
| CODESYS OPC DA Server | All versions |
CPE
Remediation
| |
| CODESYS PLCHandler | All versions |
CPE
Remediation
| |
| CODESYS Runtime Toolkit | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion