VulnSea

Eclipse Foundation has 15 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 15. The median CVSS is 8.3 (high), with 4 rated critical. None have a confirmed exploitation report. Most affected products: Eclipse Ankaios (4), Eclipse Jetty (3), @eclipse-ditto/ditto-javascript-client-node (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.3
Publish → KEV
Last 90 days
15 prev 0

Products

  • Eclipse Ankaios 4
  • Eclipse Jetty 3
  • @eclipse-ditto/ditto-javascript-client-node 1
  • Eclipse Che 1
  • Eclipse Data Plane Core 1
  • Eclipse Embedded CDT (C/C++ Development Tools) 1
15
Total CVEs
4
Critical
0
CISA KEV
0
Exploited

Eclipse Foundation vulnerabilities

CVEs affecting Eclipse Foundation, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-92612Low· 1.0PoC
today

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can…

TwilightEclipse Foundation · Eclipse iceoryx™via NVD
CVE-2025-12999Critical· 9.1PoC
today

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

AbyssalEclipse Foundation · Eclipse Open VSXEPSS 0.40%via NVD
CVE-2026-92611Medium· 4.8
4d ago

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.21%via NVD
CVE-2026-86836High· 8.4
1w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a dir…

TwilightEclipse Foundation · Eclipse AnkaiosEPSS 0.09%via NVD
CVE-2026-88819Medium· 6.3
1w ago

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

SunlitEclipse Foundation · Eclipse Data Plane CoreEPSS 0.12%via NVD
CVE-2026-89321Medium· 4.3
1w ago

Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}…

Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}…

SunlitEclipse Foundation · Eclipse OpenVSXEPSS 0.27%via NVD
CVE-2026-78299Critical· 9.1
1w ago

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

MidnightEclipse Foundation · Eclipse Embedded CDT (C/C++ Development Tools)EPSS 0.35%via NVD
CVE-2026-84197Critical· 9.2
1w ago

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, th…

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, th…

MidnightEclipse Foundation · @eclipse-ditto/ditto-javascript-client-nodeEPSS 0.20%via NVD
CVE-2026-86464Critical· 9.9
1w ago

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

MidnightEclipse Foundation · Eclipse aeriOSEPSS 0.35%via NVD
CVE-2026-19203High· 8.3
1w ago

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
CVE-2026-86590Medium· 6.3PoC
1w ago

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can ex…

TwilightEclipse Foundation · Eclipse CheEPSS 0.37%via NVD
CVE-2026-12611High· 8.7
1w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-85201Medium· 6.8
2w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access c…

SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVE-2026-84173High· 8.3PoC
2w ago

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by su…

MidnightEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVE-2026-19204High· 8.7
2w ago

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
Eclipse Foundation vulnerabilities (CVEs) · VulnSea