Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.6
CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …
Glassfish
8.0.4+
HIGH 7.5
CVE-2026-46581
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a…
Mojarra
after 4.1.13
HIGH 7.5
CVE-2026-61891
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/…
Theia
1.74.0+
HIGH 8.8
CVE-2026-60009
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…
Theia
1.74.0+
MEDIUM 6.5
CVE-2026-14574
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va…
Theia
1.74.0+
HIGH 7.5
CVE-2026-12609
In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e…
Theia
1.74.0+
MEDIUM 5.5
CVE-2026-14304
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…
Accessibility Tools Framework
3.2.0+
HIGH 8.2
CVE-2026-58080
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe…
Milo
1.1.5+
HIGH 7.5
CVE-2026-61387
In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, …
Milo
1.1.5+
HIGH 7.5
CVE-2026-62927
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author…
Milo
1.1.5+
HIGH 7.5
CVE-2026-63252
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec…
Milo
1.1.5+
HIGH 7.4
CVE-2026-60007
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other …
Milo
1.1.5+
MEDIUM 6.5
CVE-2026-63248
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia…
Milo
1.1.5+
CRITICAL 9.1
CVE-2026-10050
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.
This was done because the initi…
Jetty
9.4.63 / 10.0.31+
CRITICAL 9.6
CVE-2026-16441
In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec…
Openj9
No fix yet
CRITICAL 9.1
CVE-2026-16439
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
Openj9
0.60.0+
HIGH 7.5
CVE-2026-16243
In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.
Omr
after 0.10.0
HIGH 8.2
CVE-2026-9561
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in au…
Kura
Mitigation only
MEDIUM 5.3
CVE-2026-8384
In Eclipse Jetty, an HTTP URI of this form:
/public;/../admin/secret.txt
results in an unresolved path of:
/public/../admin/secret.…
Jetty
12.0.35 / 12.1.9+
MEDIUM 5.3
CVE-2026-6790
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i…
Jetty
9.4.61 / 10.0.29+
HIGH 7.5
CVE-2026-15075
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request…
Vert.x
after 5.1.4
HIGH 7.5
CVE-2026-15076
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not vali…
Vert.x
after 5.1.4
MEDIUM 6.5
CVE-2026-13699
In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point …
Kuksa
No fix yet
HIGH 7.5
CVE-2024-7708
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.
This is particularly the case for 100-Cont…
Jetty
10.0.23 / 11.0.23+
HIGH 7.5
CVE-2026-10051
In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same conn…
Jetty
12.0.36 / 12.1.10+
MEDIUM 5.3
CVE-2026-12606
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to per…
Grizzly
5.0.2+
HIGH 8.7
CVE-2026-13323
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Sec…
Open Vsx
1.0.2+
MEDIUM 5.4
CVE-2026-4983
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without …
Open Vsx
0.34.1+
HIGH 7.5
CVE-2026-11576
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,…
Threadx Netx Duo
after 6.5.0.202601
HIGH 8.8
CVE-2026-44691
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed …
Theia
1.69.0+