PatchSiren

Eclipse Foundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Eclipse Foundation CVE published 2026-09-21

CVE-2026-92612

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-21T11:17:12.590Z and has not been modified since then. The vulnerability affects Eclipse iceoryx2 versions greater than v0.8.0, allowing creation of invalid &str and triggering undefined behavior using entirely safe Rust. Defenders of Rust applications using affected versions should assess exposure [truncated]

CRITICAL Eclipse Foundation CVE published 2026-09-21

CVE-2025-12999

CVE-2025-12999 is a critical vulnerability in the Open VSX extension manager that allows an unauthenticated remote attacker to poison the cache with attacker-controlled download, signature, and public-key URLs, potentially leading to the installation of malicious VSIX extensions in downstream VS Code-compatible editors. The vulnerability arises from the insecure use of X-Forwarded-Host, X-Forwarded-Proto, [truncated]

MEDIUM Eclipse Foundation CVE published 2026-09-17

CVE-2026-92611

CVE-2026-92611 is a medium-severity vulnerability in Eclipse Ankaios versions 0.6.0 to before 1.0.4. The `LogRule::matches` function in the agent control-interface authorizer incorrectly stops at the first wildcard pattern in a single rule, potentially allowing unauthorized access to logs by skipping deny `LogRule` entries. This vulnerability could allow defenders and administrators to assess exposure and [truncated]

MEDIUM Eclipse Foundation CVE published 2026-09-08

CVE-2026-86590

CVE-2026-86590 is a server-side request forgery (SSRF) vulnerability in Eclipse Che versions 7.79.0 through 7.121.0. An authenticated user can exploit this to read responses from internal network addresses. The vulnerability is fixed in version 7.122.0. Defenders should assess exposure, apply the vendor-provided patch, and monitor for potential exploitation attempts. The operator-configured allowlist is n [truncated]

MEDIUM Eclipse Foundation CVE published 2026-09-07

CVE-2026-85201

CVE-2026-85201 is a vulnerability in Eclipse Ankaios versions 0.1.0 through 1.0.1 where an agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. This can cause an unbounded memory allocation that may abort the Ankaios agent process, resulting in loss of orchestration services for workloads managed by the affected agent.

HIGH Eclipse Foundation CVE published 2026-09-07

CVE-2026-19204

CVE-2026-19204 is a high-severity vulnerability in Jetty, a Java-based web server and servlet engine. A client can send a WebSocket frame with an unknown opcode and a large declared payload length, potentially causing a large memory allocation and exhausting the JVM heap when auto-fragmentation is enabled. This vulnerability affects systems using Jetty with WebSocket and auto-fragmentation enabled. Defend [truncated]

HIGH Eclipse Foundation CVE published 2026-09-07

CVE-2026-84173

CVE-2026-84173 is a high-severity vulnerability in Eclipse Ankaios versions v0.5.1 through v1.0.1. The agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. This may result in unauthorized disclosure or modification of other workloads and cluster configuration. The vulnerability allows an authenticated workload with access restricte [truncated]

CRITICAL Eclipse Foundation CVE published 2026-09-02

CVE-2026-82955

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T15:17:44.860Z and has not been modified since then. The NVD entry is currently Deferred. The CVE-2026-82955 vulnerability involves a hard-coded disable_jwk_security parameter in the KrakenD instance of the Eclipse aeriOS development version's API Gateway component. This setting disables TLS certi [truncated]

HIGH Eclipse Foundation CVE published 2026-09-02

CVE-2026-82958

Eclipse Ditto versions [1.3.0, 3.9.6] contain a vulnerability in the ImplicitThingCreationMessageMapper of the connectivity service. This vulnerability allows an attacker to inject an inline policy object by publishing a message with a specially crafted header, potentially gaining full read/write access to a newly created digital twin and revoking the legitimate owner's access.

CRITICAL Eclipse Foundation CVE published 2026-08-28

CVE-2026-18918

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T12:16:27.150Z and has not been modified since then. This critical vulnerability affects Eclipse Lyo versions 2.0.0 to 7.0.0, allowing for OAuth server authorization checks bypass when 2-legged auth is supported. Applications using Lyo-provided AbstractAdapterCredentialsFilter for authz filters ar [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-27

CVE-2026-79653

CVE-2026-79653 is a path traversal vulnerability in Eclipse SW360. The vulnerability occurs in versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, and 20.1.0 when the system is configured to use file system storage with the config key enable.attachment.store.to.file.system. An attacker can manipulate filenames upon upload to cause arbitrary file path traversal. Organizations should verify their configurations and co [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-19

CVE-2026-16440

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T11:16:46.183Z and has not been modified since then. This vulnerability affects Eclipse OpenJ9 versions up to 0.60, causing a segmentation fault with deeply nested annotations in a crafted .class file. Users and administrators should review and apply patches or updates. Limited source detail avail [truncated]

HIGH Eclipse Foundation CVE published 2026-08-14

CVE-2026-19884

Eclipse Theia versions up to and including 1.69.0 have a vulnerability that allows arbitrary command execution with user privileges when opening a folder containing an attacker-supplied .git/config. This affects applications built on Theia that include the git integration, such as the Theia IDE. The vulnerability is caused by Theia's own @theia/git extension and the builtin VS Code git extension running g [truncated]

CRITICAL Eclipse Foundation CVE published 2026-08-06

CVE-2026-12605

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T14:16:20.887Z and has not been modified since then. The vulnerability affects Eclipse GlassFish versions 8.0.x before 8.0.4. A CSRF and SSRF vulnerability in DownloadServlet ContentSources leaks the admin `gfresttoken` to an attacker-controlled host if the victim is authenticated into the Admin C [truncated]

HIGH Eclipse Foundation CVE published 2026-08-05

CVE-2026-46581

The CVE-2026-46581 vulnerability affects Eclipse Mojarra versions 2.3 and later, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd. Organizations should prioritize patching to prevent potential remote code e [truncated]

HIGH Eclipse Foundation CVE published 2026-08-05

CVE-2026-60009

In CVE-2026-60009, a vulnerability exists in Eclipse Theia versions up to and including 1.73.1. The @theia/filesystem backend binds POST /file-upload, allowing an attacker to supply an absolute path and write files without authentication or workspace confinement. This can lead to remote code execution by overwriting critical files. The vulnerability is particularly concerning in browser (non-Electron) dep [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-05

CVE-2026-14574

The CVE-2026-14574 record describes a prototype pollution vulnerability in Eclipse Theia versions 0.7.0 through 1.73.1. This vulnerability is caused by the `PreferenceUtils.merge` function in `@theia/core`, which recursively merges preference values without rejecting prototype-related keys. A crafted preference value in a workspace settings file can pollute `Object.prototype` when the user opens the works [truncated]

MEDIUM Eclipse Foundation CVE published 2026-08-05

CVE-2026-14304

The Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 and miChecker versions up to 3.1.0 contain an XML External Entity (XXE) vulnerability. This vulnerability could allow a malicious third party to gain access to local resources or internal network resources via computers running applications that use Eclipse ACTF. The CVE record was published on 2026-08-05T11:16:24.887Z and has not been [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16441

CVE-2026-16441 is a vulnerability in Eclipse OpenJ9 versions up to 0.60. When executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method. The CVSS score is 6.9, and the severity is MEDIUM. This vulnerability affects users of Eclipse OpenJ9 versions up to 0.60, who should be aware of this vulnerabili [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16243

A vulnerability was found in Eclipse OMR versions up to 0.11. The arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero. This issue has been addressed in the Eclipse OMR project. Users should review the official advisory for affected scope and severity. The issue could potentially lead to unexpected behavior or crashes if exploited. Affected users should take im [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-21

CVE-2026-16454

CVE-2026-16454 is a medium-severity privilege escalation vulnerability in Eclipse hawkBit versions 1.0.3 and prior. The vulnerability exists in the Direct Device Integration (DDI) Controller and allows an authenticated device to escalate its permissions and bypass update restrictions. This issue stems from flawed object-level authorization validation, enabling any authenticated device within the same tena [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-9561

CVE-2026-9561 is a high-severity vulnerability in Eclipse Kura versions prior to 5.6.2. The vulnerability allows unauthenticated remote attackers to bypass IP-based brute-force protections by spoofing the logged IP address. This is achieved by exploiting the trust in the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The affected prod [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-8384

CVE-2026-8384 is a medium-severity vulnerability in Eclipse Jetty, an open-source web server and servlet container. An HTTP URI of a specific form results in an unresolved path, potentially confusing web applications that rely on resolved paths. Jetty itself is not affected due to its alias checker, but web applications relying on resolved paths may be impacted. Users of Eclipse Jetty and web applications [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-6790

CVE-2026-6790 is a medium-severity vulnerability in Eclipse Jetty, a popular Java-based web server and servlet engine. The issue arises from the lack of strict checks ensuring that the request authority (host and port) matches the Host header for HTTP/1, HTTP/2, and HTTP/3 requests. This mismatch can lead to various problems, including URI construction issues, virtual host selection problems, reverse prox [truncated]

CRITICAL Eclipse Foundation CVE published 2026-07-14

CVE-2026-57898

A critical vulnerability CVE-2026-57898 was found in Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12. This issue allows an unauthenticated attacker to write arbitrary files through the AAS thumbnail API when using the MongoDB backend. The vulnerability is caused by the lack of normalization and restriction of file paths, enabling attackers to upload files to any location on [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-15076

CVE-2026-15076 is a high-severity vulnerability in Eclipse Vert.x Web Client that allows attackers to inject cookies scoped to arbitrary third-party domains. This issue arises from the WebClientSession component's failure to validate the Domain attribute of a Set-Cookie response header, violating RFC 6265 section 5.3. An attacker controlling any server contacted by the victim application can exploit this [truncated]

HIGH Eclipse Foundation CVE published 2026-07-14

CVE-2026-15075

CVE-2026-15075 is a vulnerability in Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch). The DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. This can lead to credential hea [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-13699

CVE-2026-13699 is a vulnerability in the Eclipse KUKSA Databroker version 0.6.1. The `kuksa.val.v2.VAL/PublishValue` gRPC handler fails to validate the existence of the optional `data_point` field in `PublishValueRequest`. When a request contains a valid `signal_id` but omits `data_point`, the server directly calls `unwrap()` on `request.data_point`, triggering a panic in the Tokio worker thread. This iss [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-12606

CVE-2026-12606 is a vulnerability in Eclipse Grizzly that can be leveraged to perform HTTP request smuggling due to improper parsing of the trailer section in a malformed trailer header's line. This issue affects users of Eclipse Grizzly versions before 5.0.2. The vulnerability has a CVSS score of 6.3 and a severity rating of MEDIUM. The CVE record was published on 2026-07-14T09:16:39.920Z and has not bee [truncated]

MEDIUM Eclipse Foundation CVE published 2026-07-14

CVE-2026-10051

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T09:16:39.783Z and has not been modified since then. This vulnerability affects Eclipse Jetty, specifically impacting how it handles HTTP/1.1 requests with trailers. The issue causes the server to retain trailers from the first request in subsequent requests over the same connection, potentially l [truncated]