Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-12605 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled … Glassfish 8.0.4+ Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-46581 In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a… Mojarra after 4.1.13 Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-61891 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/… Theia 1.74.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-60009 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen… Theia 1.74.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-14574 In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va… Theia 1.74.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-12609 In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e… Theia 1.74.0+ Fix from $1,9502026-08-05 MEDIUM 5.5 CVE-2026-14304 In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe… Accessibility Tools Framework 3.2.0+ Fix from $1,6002026-08-05 HIGH 8.2 CVE-2026-58080 In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe… Milo 1.1.5+ Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-61387 In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, … Milo 1.1.5+ Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-62927 In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author… Milo 1.1.5+ Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-63252 In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec… Milo 1.1.5+ Fix from $1,9502026-08-04 HIGH 7.4 CVE-2026-60007 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other … Milo 1.1.5+ Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-63248 In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia… Milo 1.1.5+ Fix from $1,6002026-08-04 CRITICAL 9.1 CVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initi… Jetty 9.4.63 / 10.0.31+ Fix from $2,3002026-08-04 CRITICAL 9.6 CVE-2026-16441 In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec… Openj9 No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-16439 In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. Openj9 0.60.0+ Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-16243 In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero. Omr after 0.10.0 Fix from $1,9502026-07-21 HIGH 8.2 CVE-2026-9561 Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in au… Kura Mitigation only Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-8384 In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.… Jetty 12.0.35 / 12.1.9+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-6790 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i… Jetty 9.4.61 / 10.0.29+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-15075 In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request… Vert.x after 5.1.4 Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-15076 In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not vali… Vert.x after 5.1.4 Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-13699 In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point … Kuksa No fix yet Fix from $1,6002026-07-14 HIGH 7.5 CVE-2024-7708 For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Cont… Jetty 10.0.23 / 11.0.23+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-10051 In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same conn… Jetty 12.0.36 / 12.1.10+ Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-12606 Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to per… Grizzly 5.0.2+ Fix from $1,6002026-07-14 HIGH 8.7 CVE-2026-13323 In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Sec… Open Vsx 1.0.2+ Fix from $1,9502026-07-01 MEDIUM 5.4 CVE-2026-4983 Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without … Open Vsx 0.34.1+ Fix from $1,6002026-06-23 HIGH 7.5 CVE-2026-11576 The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,… Threadx Netx Duo after 6.5.0.202601 Fix from $1,9502026-06-19 HIGH 8.8 CVE-2026-44691 In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed … Theia 1.69.0+ Fix from $1,9502026-06-18