CVE-2026-76992: high-severity vulnerability in CODESYS Gateway
Uncontrolled Memory Allocation in CODESYS Gateway Client
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
CODESYS · Development System 3CODESYS · Edge Gateway for LinuxCODESYS · Edge Gateway for WindowsCODESYS · GatewayCODESYS · HMI (SL)CODESYS · OPC DA Server SLCODESYS · PLCHandlerCODESYS · Runtime ToolkitRelated CVEs — CODESYS Gateway
In the same product, most dangerous first.