VulnSea

eclipse has 14 CVEs on record between 2021 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was July 2026 with 4. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: jetty (3), org.eclipse.jetty:jetty-server (2), 4diac_forte (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
4 prev 4

Products

  • jetty 3
  • org.eclipse.jetty:jetty-server 2
  • 4diac_forte 1
  • github.com/eclipse/paho.mqtt.golang 1
  • glassfish 1
  • grizzly 1
14
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

eclipse vulnerabilities

CVEs affecting eclipse, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-6790Medium· 5.3
2mo ago

Eclipse Jetty: HTTP Authority/Host mismatch

Eclipse Jetty: HTTP Authority/Host mismatch

Sunliteclipse · org.eclipse.jetty:jetty-serverEPSS 0.31%via GHSA
CVE-2026-8384Medium· 5.3
2mo ago

Eclipse Jetty: Path parameter traversal

Eclipse Jetty: Path parameter traversal

Sunliteclipse · org.eclipse.jetty:jetty-utilEPSS 0.33%via GHSA
CVE-2024-7708High· 7.5
2mo ago

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Twilighteclipse · org.eclipse.jetty:jetty-serverEPSS 0.44%via GHSA
CVE-2026-12606Medium· 5.3
2mo ago

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the be…

Sunliteclipse · grizzlyEPSS 0.30%via NVD
CVE-2026-11576High· 7.5
3mo ago

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

Twilighteclipse · threadx_netx_duoEPSS 0.46%via NVD
CVE-2026-9158Critical· 9.8
3mo ago

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Midnighteclipse · 4diac_forteEPSS 0.60%via NVD
CVE-2026-2332High· 7.4PoC
5mo ago

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

Midnighteclipse · jettyEPSS 1.3%via NVD
CVE-2026-5795High· 7.4
5mo ago

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator…

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator…

Twilighteclipse · jettyEPSS 0.53%via NVD
CVE-2026-24457Critical· 9.1
6mo ago

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In s…

Midnighteclipse · openmqEPSS 0.62%via NVD
CVE-2026-1605High· 7.5
6mo ago

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This hap…

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This hap…

Twilighteclipse · jettyEPSS 0.67%via NVD
CVE-2025-10543Medium
9mo ago

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

Sunliteclipse · github.com/eclipse/paho.mqtt.golangEPSS 0.23%via OSV
CVE-2025-7962High· 7.5
1y ago

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

Twilighteclipse · jakarta_mailEPSS 0.77%via NVD
CVE-2022-2712Medium· 6.5
3y ago

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to acces…

Sunliteclipse · glassfishEPSS 0.94%via NVD
CVE-2021-34432High· 7.5
5y ago

In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

Twilighteclipse · mosquittoEPSS 1.2%via NVD
eclipse vulnerabilities (CVEs) · VulnSea