PatchSiren

Eclipse CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Eclipse CVE published 2026-08-04

CVE-2026-63252

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:55.913Z and has not been modified since then. CVE-2026-63252 affects Eclipse Milo versions 0.6.0 through 1.1.4. The UASC server transport handlers fail to release retained partial message chunks when a channel disconnects. A remote unauthenticated client can exploit this by repeatedly sendi [truncated]

MEDIUM Eclipse CVE published 2026-08-04

CVE-2026-63248

Eclipse Milo, a popular implementation of the OPC UA protocol, contains a vulnerability in versions 0.6.0 through 1.1.4 that allows unauthorized access to diagnostics nodes. This oversight enables an anonymous client to activate diagnostics over a None/None endpoint without a certificate. Furthermore, a trusted client application with a certificate over SignAndEncrypt can access security diagnostics for o [truncated]

HIGH Eclipse CVE published 2026-08-04

CVE-2026-62927

The CVE-2026-62927 vulnerability affects Eclipse Milo versions 1.0.0 through 1.1.4. It is caused by the Call service dispatching the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or low-privileged client to execute a denied method by batching it with an allowed method. This could lead to high-severity attacks. Eclipse Milo users, administrators of af [truncated]

MEDIUM Eclipse CVE published 2026-08-04

CVE-2026-61387

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:55.543Z and has not been modified since then. Eclipse Milo versions 1.0.0 through 1.1.4 are affected by a vulnerability in monitored-item quota accounting, which is not exception-safe. A deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can trigger a StackOverflow [truncated]

CRITICAL Eclipse CVE published 2026-08-04

CVE-2026-60007

CVE-2026-60007 is a critical vulnerability in Eclipse Milo versions 0.6.0 through 1.1.4. An on-path attacker can capture a victim's Basic128Rsa15-encrypted username token and use repeated unauthenticated ActivateSession requests as a padding oracle to recover the victim's password and authenticate with the recovered credentials. This vulnerability allows an attacker to gain unauthorized access to affected [truncated]

HIGH Eclipse CVE published 2026-08-04

CVE-2026-58080

The CVE-2026-58080 vulnerability affects Eclipse Milo versions 1.0.0 through 1.1.4. The issue arises from the `OpcUaServerConfig.copy()` method failing to preserve a configured `RoleMapper`. This vulnerability class relates to improper preservation of role permissions during configuration copying. The likely operational impact includes unauthorized access to role-permission metadata, invocation of protect [truncated]

HIGH Eclipse CVE published 2026-08-04

CVE-2026-10050

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T11:22:43.883Z and has not been modified since then. The NVD entry is currently Analyzed. Eclipse Jetty's Digest authentication server-side component uses ISO-8859-1 to encode passwords, which can lead to silent replacement of non-ISO-8859-1 characters with `?`. An attacker can exploit this by sen [truncated]

HIGH Eclipse CVE published 2026-03-05

CVE-2026-1605

CVE-2026-1605 is a high-severity vulnerability in Eclipse Jetty, specifically affecting the GzipHandler component. The vulnerability occurs when a compressed HTTP request with Content-Encoding: gzip is processed, and the corresponding response is not compressed. This causes a resource leak because the JDK Inflater is allocated for decompression but not released, as the release mechanism is tied to the com [truncated]