---
id: CVE-2026-85201
title: >-
  In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the
  length declared by a workload in a length-delimited protobuf message received
  through the Control Interface FIFO
summary: >-
  In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the
  length declared by a workload in a length-delimited protobuf message received
  through the Control Interface FIFO. A workload granted Control Interface
  access c…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'
cwe:
  - CWE-789
  - CWE-1284
vendor: Eclipse Foundation
product: Eclipse Ankaios
affected:
  - eclipse_ankaios >= 0.1.0 <= 1.0.1
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:18:19.040'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85201'
references:
  - url: 'https://github.com/eclipse-ankaios/ankaios/pull/791'
    label: emo@eclipse.org
  - url: 'https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.2'
    label: emo@eclipse.org
  - url: 'https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/900'
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T15:05:01.649513Z'
cvssSource: cna
epss: 0.00112
epssPercentile: 0.01534
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
