<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:codesys:gateway_client:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acodesysgateway_client/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 14:35:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acodesysgateway_client/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial-of-Service Vulnerability in CODESYS Gateway Client</title><link>https://feed.craftedsignal.io/briefs/2026-09-codesys-gateway-dos/</link><pubDate>Wed, 30 Sep 2026 14:35:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-codesys-gateway-dos/</guid><description>An unauthenticated remote attacker can cause a denial-of-service in the CODESYS Gateway Client by providing a malicious gateway response that forces excessive memory allocation.</description><content:encoded><![CDATA[<p>The CODESYS Gateway Client is susceptible to a denial-of-service vulnerability (CVE-2026-76992) caused by improper input validation. The application allocates memory based on a size field provided within a gateway response without verifying if that size exceeds reasonable or safe limits. An unauthenticated, remote attacker who controls a malicious or compromised gateway server can send a crafted response with an abnormally large size value. When the Gateway Client attempts to process this response, it performs an oversized memory allocation, leading to exhaustion of system resources and a total loss of availability for the service. This vulnerability highlights the importance of enforcing strict validation on all data structures received from untrusted or external network infrastructure components.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to a denial-of-service condition, rendering the CODESYS Gateway Client unresponsive. This impact is critical for environments relying on CODESYS for industrial automation and process control, as the loss of gateway availability disrupts communication between the engineering environment and field devices.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Audit network egress and ingress traffic to identify unauthorized or rogue CODESYS gateway servers communicating with the local Gateway Client.</li>
<li>Implement network segmentation to ensure that the Gateway Client only communicates with verified and trusted gateway endpoints.</li>
<li>Apply patches for CVE-2026-76992 as soon as they are made available by the vendor to remediate the unsafe memory allocation logic.</li>
<li>Monitor system logs for unexpected application crashes or resource exhaustion events involving the CODESYS Gateway Client process.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>denial-of-service</category></item></channel></rss>