PatchSiren

Eclipse Foundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Eclipse Foundation CVE published 2026-08-14

CVE-2026-19884

Eclipse Theia versions up to and including 1.69.0 have a vulnerability that allows arbitrary command execution with user privileges when opening a folder containing an attacker-supplied .git/config. This affects applications built on Theia that include the git integration, such as the Theia IDE. The vulnerability is caused by Theia's own @theia/git extension and the builtin VS Code git extension running g [truncated]

CRITICAL Eclipse Foundation CVE published 2026-08-06

CVE-2026-12605

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:20.887Z and has not been modified since then. The vulnerability affects Eclipse GlassFish versions 8.0.x before 8.0.4. A CSRF and SSRF vulnerability in DownloadServlet ContentSources leaks the admin `gfresttoken` to an attacker-controlled host if the victim is authenticated into the Admin C [truncated]

HIGH Eclipse Foundation CVE published 2026-08-05

CVE-2026-46581

The CVE-2026-46581 vulnerability affects Eclipse Mojarra versions 2.3 and later, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd. Organizations should prioritize patching to prevent potential remote code e [truncated]

HIGH Eclipse Foundation CVE published 2026-08-05

CVE-2026-60009

In CVE-2026-60009, a vulnerability exists in Eclipse Theia versions up to and including 1.73.1. The @theia/filesystem backend binds POST /file-upload, allowing an attacker to supply an absolute path and write files without authentication or workspace confinement. This can lead to remote code execution by overwriting critical files. The vulnerability is particularly concerning in browser (non-Electron) dep [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-05

CVE-2026-14574

The CVE-2026-14574 record describes a prototype pollution vulnerability in Eclipse Theia versions 0.7.0 through 1.73.1. This vulnerability is caused by the `PreferenceUtils.merge` function in `@theia/core`, which recursively merges preference values without rejecting prototype-related keys. A crafted preference value in a workspace settings file can pollute `Object.prototype` when the user opens the works [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-05

CVE-2026-14304

The Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 and miChecker versions up to 3.1.0 contain an XML External Entity (XXE) vulnerability. This vulnerability could allow a malicious third party to gain access to local resources or internal network resources via computers running applications that use Eclipse ACTF. The CVE record was published on 2026-08-05T11:16:24.887Z and has not been [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16441

CVE-2026-16441 is a vulnerability in Eclipse OpenJ9 versions up to 0.60. When executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method. The CVSS score is 6.9, and the severity is MEDIUM. This vulnerability affects users of Eclipse OpenJ9 versions up to 0.60, who should be aware of this vulnerabili [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16243

A vulnerability was found in Eclipse OMR versions up to 0.11. The arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero. This issue has been addressed in the Eclipse OMR project. Users should review the official advisory for affected scope and severity. The issue could potentially lead to unexpected behavior or crashes if exploited. Affected users should take im [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16454

CVE-2026-16454 is a medium-severity privilege escalation vulnerability in Eclipse hawkBit versions 1.0.3 and prior. The vulnerability exists in the Direct Device Integration (DDI) Controller and allows an authenticated device to escalate its permissions and bypass update restrictions. This issue stems from flawed object-level authorization validation, enabling any authenticated device within the same tena [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-9561

CVE-2026-9561 is a high-severity vulnerability in Eclipse Kura versions prior to 5.6.2. The vulnerability allows unauthenticated remote attackers to bypass IP-based brute-force protections by spoofing the logged IP address. This is achieved by exploiting the trust in the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The affected prod [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-8384

CVE-2026-8384 is a medium-severity vulnerability in Eclipse Jetty, an open-source web server and servlet container. An HTTP URI of a specific form results in an unresolved path, potentially confusing web applications that rely on resolved paths. Jetty itself is not affected due to its alias checker, but web applications relying on resolved paths may be impacted. Users of Eclipse Jetty and web applications [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-6790

CVE-2026-6790 is a medium-severity vulnerability in Eclipse Jetty, a popular Java-based web server and servlet engine. The issue arises from the lack of strict checks ensuring that the request authority (host and port) matches the Host header for HTTP/1, HTTP/2, and HTTP/3 requests. This mismatch can lead to various problems, including URI construction issues, virtual host selection problems, reverse prox [truncated]

CRITICAL Eclipse Foundation CVE published 2026-07-14

CVE-2026-57898

A critical vulnerability CVE-2026-57898 was found in Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12. This issue allows an unauthenticated attacker to write arbitrary files through the AAS thumbnail API when using the MongoDB backend. The vulnerability is caused by the lack of normalization and restriction of file paths, enabling attackers to upload files to any location on [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-15076

CVE-2026-15076 is a high-severity vulnerability in Eclipse Vert.x Web Client that allows attackers to inject cookies scoped to arbitrary third-party domains. This issue arises from the WebClientSession component's failure to validate the Domain attribute of a Set-Cookie response header, violating RFC 6265 section 5.3. An attacker controlling any server contacted by the victim application can exploit this [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-15075

CVE-2026-15075 is a vulnerability in Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch). The DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. This can lead to credential hea [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-13699

CVE-2026-13699 is a vulnerability in the Eclipse KUKSA Databroker version 0.6.1. The `kuksa.val.v2.VAL/PublishValue` gRPC handler fails to validate the existence of the optional `data_point` field in `PublishValueRequest`. When a request contains a valid `signal_id` but omits `data_point`, the server directly calls `unwrap()` on `request.data_point`, triggering a panic in the Tokio worker thread. This iss [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-12606

CVE-2026-12606 is a vulnerability in Eclipse Grizzly that can be leveraged to perform HTTP request smuggling due to improper parsing of the trailer section in a malformed trailer header's line. This issue affects users of Eclipse Grizzly versions before 5.0.2. The vulnerability has a CVSS score of 6.3 and a severity rating of MEDIUM. The CVE record was published on 2026-07-14T09:16:39.920Z and has not bee [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-10051

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T09:16:39.783Z and has not been modified since then. This vulnerability affects Eclipse Jetty, specifically impacting how it handles HTTP/1.1 requests with trailers. The issue causes the server to retain trailers from the first request in subsequent requests over the same connection, potentially l [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2024-7708

A buffer leak vulnerability exists for requests with bodies where reading may result in 0 bytes being read. This issue is particularly noted in 100-Continue requests but can occur with any request over a slow network. The vulnerability can lead to potential information disclosure and is considered a high priority due to its potential impact. Users of affected software should be aware of this vulnerability [truncated]

HIGH Eclipse Foundation CVE published 2026-07-03

CVE-2026-10054

Eclipse Theia versions 1.8.1 and later have a vulnerability in the browser backend that exposes privileged terminal RPC over WebSocket without service-level authentication. This allows a foreign-origin web page to invoke terminal creation, execute arbitrary OS commands, and read their output. The vulnerability arises from fail-open WebSocket origin validation in @theia/core and the replacement of the real [truncated]

MEDIUM Eclipse Foundation CVE published 2026-06-29

CVE-2026-9267

CVE-2026-9267 is an out-of-bounds read vulnerability in the check_server_certificate() function of Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221. This vulnerability allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a specific fragment_length value. The vulnerability is caused by missing buffer length [truncated]

MEDIUM Eclipse Foundation CVE published 2026-06-23

CVE-2026-4983

CVE-2026-4983 is a stored cross-site scripting (XSS) vulnerability in the Open VSX Registry. The vulnerability arises from the lack of sanitization of SVG files uploaded as extension icons before they are stored. These SVG files are served with a Content-Type of image/svg+xml and without security headers such as Content-Security-Policy or Content-Disposition: attachment. An attacker can exploit this by pu [truncated]

HIGH Eclipse Foundation CVE published 2026-06-18

CVE-2026-46580

CVE-2026-46580 is a HIGH-severity vulnerability in Eclipse Theia, a cloud-native, multi-protocol IDE framework. In versions prior to 1.71.0, Theia automatically loaded files matching the pattern `.prompts/*.prompttemplate` in a workspace, allowing an attacker to craft malicious repository containing prompt template files. When a workspace was opened in Theia, these files could replace the AI's system inst [truncated]

HIGH Eclipse Foundation CVE published 2026-06-18

CVE-2026-44691

CVE-2026-44691 is a high-severity vulnerability in Eclipse Theia, a cloud-native, open-source, extensible, desktop and web-based integrated development environment (IDE). The issue allows custom task definitions in workspace files (e.g., .theia/tasks.json, .vscode/tasks.json) to be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Th [truncated]

MEDIUM Eclipse Foundation CVE published 2026-06-18

CVE-2026-22551

Eclipse Theia versions prior to 1.71.0 contain a vulnerability (CVE-2026-22551) that allows attackers to exfiltrate sensitive information via AI chat rendered Markdown image tags. The vulnerability has a CVSS score of 6.7 and is classified as MEDIUM severity. An attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, sending it [truncated]

MEDIUM Eclipse Foundation CVE published 2026-06-18

CVE-2026-9158

CVE-2026-9158 is a medium-severity vulnerability in Eclipse 4diac FORTE versions 3.0.0 to 3.1.0. A specially crafted DELETE connection command to the management interface can lead to a dangling pointer, allowing subsequent commands to access freed memory (use-after-free). This issue was published on June 18, 2026, and has a CVSS score of 5.2. Users of affected versions should take immediate action to miti [truncated]

CRITICAL Eclipse Foundation CVE published 2026-05-19

CVE-2026-2587

CVE-2026-2587 describes a critical server-side Expression Language (EL) injection issue in a Glassfish-related gadget handling path. The supplied description indicates that untrusted values from .xml input are evaluated without proper sanitization or escaping, and a test payload such as #{7*7} returns 49, confirming server-side expression evaluation. The reported impact is severe: remote attackers may be [truncated]

CRITICAL Eclipse Foundation CVE published 2026-05-19

CVE-2026-2586

CVE-2026-2586 is a critical authenticated remote code execution issue in GlassFish’s Administration Console. The supplied record says a user with access to the panel can send crafted requests that lead to arbitrary operating system command execution under the privileges of the application service user. Because exploitation requires high privileges but no user interaction, and the impact spans confidential [truncated]

HIGH Eclipse Foundation CVE published 2026-05-05

CVE-2026-7412

A design flaw in Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10 allows unauthenticated remote attackers to execute blind HTTP POST requests to arbitrary internal or external targets. This vulnerability has a high impact due to its potential for unauthorized access and lateral movement. Users of affected versions should assess their exposure and apply patches or mitigations. The vulnera [truncated]

HIGH Eclipse Foundation CVE published 2026-05-05

CVE-2026-6918

CVE-2026-6918 is a high-severity vulnerability in Eclipse Open9J versions 0.21 to 0.58. A pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. This issue has been publicly disclosed and has a CVSS score of 8.7. The vulnerability affects Eclipse Open9J versions between 0.21.0 and 0.59.0. Users of affected versions should apply patches or mitigations provided by t [truncated]

CRITICAL Eclipse Foundation CVE published 2026-03-05

CVE-2026-24457

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-05T19:16:02.780Z and has not been modified since then. This critical vulnerability, CVE-2026-24457, affects OpenMQ versions less than 6.5.2 and less than 6.9.0, allowing remote attackers to read arbitrary files from a MQ Broker's server, potentially leading to Remote Code Execution (RCE) in some sce [truncated]