Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Glassfish CRITICAL 9.6
CVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …

Fix: 8.0.4+
Fix from $2,300 2026-08-06
Mojarra HIGH 7.5
CVE-2026-46581

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a…

Fix: after 4.1.13
Fix from $1,950 2026-08-05
Theia HIGH 7.5
CVE-2026-61891

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Theia HIGH 8.8
CVE-2026-60009

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Theia MEDIUM 6.5
CVE-2026-14574

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va…

Fix: 1.74.0+
Fix from $1,600 2026-08-05
Theia HIGH 7.5
CVE-2026-12609

In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Accessibility Tools Framework MEDIUM 5.5
CVE-2026-14304

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…

Fix: 3.2.0+
Fix from $1,600 2026-08-05
Milo HIGH 8.2
CVE-2026-58080

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-61387

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, …

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-62927

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-63252

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.4
CVE-2026-60007

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other …

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo MEDIUM 6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia…

Fix: 1.1.5+
Fix from $1,600 2026-08-04
Jetty CRITICAL 9.1
CVE-2026-10050

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initi…

Fix: 9.4.63 / 10.0.31+
Fix from $2,300 2026-08-04
Openj9 CRITICAL 9.6
CVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec…

No fix yet
Fix from $2,300 2026-07-21
Openj9 CRITICAL 9.1
CVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

Fix: 0.60.0+
Fix from $2,300 2026-07-21
Omr HIGH 7.5
CVE-2026-16243

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

Fix: after 0.10.0
Fix from $1,950 2026-07-21
Kura HIGH 8.2
CVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in au…

Mitigation only
Fix from $1,950 2026-07-14
Jetty MEDIUM 5.3
CVE-2026-8384

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.…

Fix: 12.0.35 / 12.1.9+
Fix from $1,600 2026-07-14
Jetty MEDIUM 5.3
CVE-2026-6790

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i…

Fix: 9.4.61 / 10.0.29+
Fix from $1,600 2026-07-14
Vert.x HIGH 7.5
CVE-2026-15075

In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request…

Fix: after 5.1.4
Fix from $1,950 2026-07-14
Vert.x HIGH 7.5
CVE-2026-15076

In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not vali…

Fix: after 5.1.4
Fix from $1,950 2026-07-14
Kuksa MEDIUM 6.5
CVE-2026-13699

In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point …

No fix yet
Fix from $1,600 2026-07-14
Jetty HIGH 7.5
CVE-2024-7708

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Cont…

Fix: 10.0.23 / 11.0.23+
Fix from $1,950 2026-07-14
Jetty HIGH 7.5
CVE-2026-10051

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same conn…

Fix: 12.0.36 / 12.1.10+
Fix from $1,950 2026-07-14
Grizzly MEDIUM 5.3
CVE-2026-12606

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to per…

Fix: 5.0.2+
Fix from $1,600 2026-07-14
Open Vsx HIGH 8.7
CVE-2026-13323

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Sec…

Fix: 1.0.2+
Fix from $1,950 2026-07-01
Open Vsx MEDIUM 5.4
CVE-2026-4983

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without …

Fix: 0.34.1+
Fix from $1,600 2026-06-23
Threadx Netx Duo HIGH 7.5
CVE-2026-11576

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,…

Fix: after 6.5.0.202601
Fix from $1,950 2026-06-19
Theia HIGH 8.8
CVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed …

Fix: 1.69.0+
Fix from $1,950 2026-06-18