vciy

CVEs we hold for Eclipse

Records whose assigning authority named Eclipse as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9563no title heldEclipse Parsson
CVE-2026-9561no title heldEclipse Kura
CVE-2026-9267no title heldEclipse tinydtls
CVE-2026-92611no title heldEclipse Ankaios
CVE-2026-9158no title heldEclipse 4diac
CVE-2026-89321no title heldEclipse OpenVSX
CVE-2026-88819no title heldEclipse Data Plane Core
CVE-2026-86836no title heldEclipse Ankaios
CVE-2026-86590no title heldEclipse Che
CVE-2026-86464no title heldEclipse aeriOS
CVE-2026-85201no title heldEclipse Ankaios
CVE-2026-85199no title heldEclipse aeriOS
CVE-2026-84736no title heldEclipse aeriOS
CVE-2026-84197no title heldEclipse Ditto
CVE-2026-84175no title heldEclipse Ditto
CVE-2026-84173no title heldEclipse Ankaios
CVE-2026-8384no title heldEclipse Jetty
CVE-2026-82958no title heldEclipse Ditto
CVE-2026-82955no title heldEclipse aeriOS
CVE-2026-82217no title heldEclipse Theia
CVE-2026-82180no title heldEclipse Arrowhead
CVE-2026-80515no title heldEclipse Arrowhead
CVE-2026-79653no title heldEclipse SW360
CVE-2026-78299no title heldEclipse Embedded CDT (C/C++ Development Tools)
CVE-2026-7412no title heldEclipse BaSyx
CVE-2026-7411no title heldEclipse BaSyx
CVE-2026-6918no title heldEclipse OpenJ9
CVE-2026-6860no title heldEclipse Vert.x
CVE-2026-6790no title heldEclipse Jetty
CVE-2026-63252no title heldEclipse Milo
CVE-2026-63248no title heldEclipse Milo
CVE-2026-62927no title heldEclipse Milo
CVE-2026-6272no title heldEclipse KUKSA - Databroker
CVE-2026-61891no title heldEclipse Theia
CVE-2026-61387no title heldEclipse Milo
CVE-2026-60009no title heldEclipse Theia
CVE-2026-60007no title heldEclipse Milo
CVE-2026-58465Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoSeclipse-wakaama wakaama
CVE-2026-58080no title heldEclipse Milo
CVE-2026-5795no title heldEclipse Jetty
CVE-2026-57898no title heldEclipse BaSyx - Java Server SDK
CVE-2026-4983no title heldEclipse Open VSX
CVE-2026-46581no title heldEclipse Mojarra
CVE-2026-46580no title heldEclipse Theia
CVE-2026-44691no title heldEclipse Theia
CVE-2026-44688no title heldEclipse Theia
CVE-2026-2587no title heldEclipse Glassfish
CVE-2026-2586no title heldEclipse Glassfish
CVE-2026-24457no title heldEclipse GlassFish
CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String ParsingEclipse Jetty
CVE-2026-22886no title heldEclipse OpenMQ
CVE-2026-22551no title heldEclipse Theia
CVE-2026-19884no title heldEclipse Theia
CVE-2026-19204no title heldEclipse Jetty
CVE-2026-19203no title heldEclipse Jetty
CVE-2026-18918OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed defaultEclipse Lyo
CVE-2026-18353Unauthenticated SSRF in PIA via OIDC issuer allowlist bypassEclipse CSI - PIA
CVE-2026-1699no title heldEclipse Theia - Website
CVE-2026-16454Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware ExfiltrationEclipse Foundation eclipse-hawkbit/hawkbit
CVE-2026-16441Eclipse OpenJ9 : Method resolution default method precedence failureEclipse Foundation OpenJ9
CVE-2026-16440no title heldEclipse OpenJ9
CVE-2026-16439Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflowEclipse Foundation OpenJ9
CVE-2026-16243Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zeroEclipse OMR
CVE-2026-1605no title heldEclipse Jetty
CVE-2026-15803no title heldEclipse RDF4J
CVE-2026-15704CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go ComponentsEclipse BaSyx Go Components
CVE-2026-15076no title heldEclipse Vert.x
CVE-2026-15075no title heldEclipse Vert.x
CVE-2026-14574no title heldEclipse Theia
CVE-2026-14336no title heldEclipse CSI - PIA
CVE-2026-14304no title heldEclipse Accessibility Tools Framework (ACTF)
CVE-2026-13699Databroker 0.6.1 PublishValue missing data_point panicEclipse KUKSA - Databroker
CVE-2026-13323no title heldEclipse Open VSX
CVE-2026-12616no title heldEclipse CSI - PIA
CVE-2026-12611no title heldEclipse Jetty
CVE-2026-12609no title heldEclipse Theia
CVE-2026-12606no title heldEclipse GlassFish
CVE-2026-12605no title heldEclipse GlassFish
CVE-2026-1188no title heldEclipse OMR
CVE-2026-11576no title heldEclipse ThreadX - NetX Duo
CVE-2026-10055no title heldEclipse Theia
CVE-2026-10054no title heldEclipse Theia
CVE-2026-10051no title heldEclipse Jetty
CVE-2026-10050Digest authentication lossy encodingEclipse Jetty
CVE-2026-1002Eclipse Vert.x Web static handler file access denialEclipse Vert.x
CVE-2026-0648no title heldEclipse ThreadX
CVE-2025-7962no title heldEclipse Foundation Jakarta Mail
CVE-2025-6705no title heldEclipse Open VSX Registry
CVE-2025-55102no title heldEclipse ThreadX - NetX Duo
CVE-2025-55100Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()Eclipse Foundation USBX
CVE-2025-55099Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()Eclipse Foundation USBX
CVE-2025-55098Potential out-of-bounds read in _ux_host_class_audio_device_type_get()Eclipse Foundation USBX
CVE-2025-55097Potential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get()Eclipse Foundation USBX
CVE-2025-55096Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get()Eclipse Foundation NetX Duo
CVE-2025-55095no title heldEclipse ThreadX - USBX
CVE-2025-55094Potential out-of-bounds read in _nx_icmpv6_validate_options()Eclipse Foundation NetX Duo
CVE-2025-55093Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messagesEclipse Foundation NetX Duo
CVE-2025-55092Potential out of bound read in _nx_ipv4_option_process()Eclipse Foundation NetX Duo
CVE-2025-55091Potential out of bound read in _nx_ip_packet_receive()Eclipse Foundation NetX Duo
CVE-2025-55090Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX DuoEclipse Foundation NetX Duo
CVE-2025-55089Eclipse ThreadX FileX RAM disk driver buffer overflowEclipse Foundation FileX
CVE-2025-55087no title heldEclipse Foundation NextX Duo
CVE-2025-55086no title heldEclipse Foundation NextX Duo
CVE-2025-55085Web http client: Unchecked Server-Side Malicious Packet IssueEclipse Foundation NetX Duo
CVE-2025-55084Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()Eclipse Foundation NetX Duo
CVE-2025-55083Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()Eclipse Foundation NetX Duo
CVE-2025-55082Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find()Eclipse Foundation NetX Duo
CVE-2025-55081Potential out of bound read in _nx_secure_tls_process_clienthello()Eclipse Foundation NetX Duo
CVE-2025-55080Improper Parameter Check in ThreadX Syscall ImplementationEclipse Foundation ThreadX
CVE-2025-55079Missing check for thread priorityEclipse Foundation ThreadX
CVE-2025-55078Incomplete validation of kernel object pointers in system callsEclipse Foundation ThreadX
CVE-2025-5115MadeYouReset HTTP/2 vulnerabilityEclipse Jetty
CVE-2025-4949XXE vulnerability in Eclipse JGitEclipse JGit
CVE-2025-4447Buffer Overflow in Eclipse OpenJ9Eclipse Foundation OpenJ9
CVE-2025-2515Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependenciesEclipse Foundation BlueChi
CVE-2025-2260Eclipse ThreadX NetX Duo HTTP component server denial of serviceEclipse Foundation ThreadX
CVE-2025-2259Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflowEclipse Foundation ThreadX
CVE-2025-2258Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflowEclipse Foundation ThreadX
CVE-2025-1948Eclipse Jetty HTTP clients can increase memory allocationEclipse Foundation Jetty
CVE-2025-1471Eclipse OMR: Buffer overflow vulnerabilityEclipse OMR
CVE-2025-1470Eclipse OMR: Null pointer dereference vulnerabilityEclipse OMR
CVE-2025-14549OMR on Z processors Exposing a possible buffer over-read problemEclipse OMR
CVE-2025-12383Race Condition allows Bypass of Trust RestrictionsEclipse Foundation Jersey
CVE-2025-11966no title heldEclipse Foundation Vert.x
CVE-2025-11965no title heldEclipse Foundation Vert.x
CVE-2025-11143no title heldEclipse Jetty
CVE-2025-10543no title heldEclipse Foundation paho.mqtt.golang (Go MQTT v3.1 library)
CVE-2025-1007Improper Authorization in /user/namespace/{namespace}/detailsEclipse Foundation OpenVSX
CVE-2025-0728Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflowEclipse Foundation ThreadX
CVE-2025-0727Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflowEclipse Foundation ThreadX
CVE-2025-0726Eclipse ThreadX NetX Duo HTTP server denial of serviceEclipse Foundation ThreadX
CVE-2024-9823Jetty DOS vulnerability on DosFilterEclipse Jetty Jetty
CVE-2024-9408no title heldEclipse Glassfish
CVE-2024-9343no title heldEclipse Glassfish
CVE-2024-9342no title heldEclipse Glassfish
CVE-2024-9329Glassfish redirect to untrusted siteEclipse Foundation Glassfish
CVE-2024-9202EDC DataSetResolver policy filtering missingEclipse Dataspace Components
CVE-2024-8646Eclipse Glassfish: URL redirection vulnerability to untrusted sitesEclipse Glassfish
CVE-2024-8642Eclipse EDC: Consumer pull transfer token validation checks not appliedEclipse EDC Connector
CVE-2024-8391Eclipse Vert.x gRPC server does not limit the maximum message sizeEclipse Vert.x
CVE-2024-8376Memory leakEclipse Foundation Mosquitto
CVE-2024-8184Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksEclipse Foundation Jetty
CVE-2024-7708no title heldEclipse Jetty
CVE-2024-6763Jetty URI parsing of invalid authorityEclipse Foundation Jetty
CVE-2024-6762Jetty PushSessionCacheFilter can cause remote DoS attacksEclipse Foundation Jetty
CVE-2024-5165Eclipse Ditto User Interface vulnerable to XSS due to Improper Neutralization of InputEclipse Ditto
CVE-2024-4536Eclipse EDC: OAuth2 Credential Exfiltration VulnerabilityEclipse Foundation EDC
CVE-2024-3935Eclipse Mosquito: Double free vulnerabilityEclipse Foundation mosquitto
CVE-2024-3933Eclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a bufferEclipse Foundation Open J9
CVE-2024-3046no title heldEclipse Foundation Kura
CVE-2024-2452Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()Eclipse Foundation ThreadX
CVE-2024-2214Missing array size check in _Mtxinit() in the Xtensa portEclipse Foundation ThreadX
CVE-2024-2212Integer wraparounds, under-allocations, and heap buffer overflows in Eclipse ThreadX xQueueCreate() and…Eclipse Foundation ThreadX
CVE-2024-13009Eclipse Jetty GZIP buffer releaseEclipse Foundation Jetty
CVE-2024-10917Eclipse OpenJ9 might return an incorrect value in JNI function GetStringUTFLengthEclipse Foundation Open J9
CVE-2024-10838Integer Underflow in DDS_Security_Deserialize_ methods may lead to OOB readEclipse Cyclone DDS
CVE-2024-10525Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callbackEclipse Foundation mosquitto
CVE-2024-10032no title heldEclipse Glassfish
CVE-2024-10031no title heldEclipse Glassfish
CVE-2024-10029no title heldEclipse Glassfish
CVE-2024-0740Eclipse Target Management <= 4.5.500 Command InjectionEclipse Target Management
CVE-2023-7272Eclipse Parsson stack overflow with deeply nested objectsEclipse Foundation Parsson
CVE-2023-6194no title heldEclipse Memory Analyzer (tools.mat)
CVE-2023-5763Glassfish remote code executionEclipse Foundation Glassfish
CVE-2023-5676Eclipse OpenJ9 possible infinite busy hangEclipse Foundation OpenJ9
CVE-2023-5632Unconditionally adding an event to the epoll causes excessive CPU consumptionEclipse Mosquitto
CVE-2023-4760Remote Code Execution in Eclipse RAP on WindowsEclipse RAP
CVE-2023-4759Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file writeEclipse JGit
CVE-2023-4218XXE in eclipse.platform / Eclipse IDEEclipse Foundation org.eclipse.pde
CVE-2023-41900Jetty's OpenId Revoked authentication allows one requesteclipse jetty.project
CVE-2023-41034DDFFileParser in eclipse leshan is vulnerable to XXE Attackseclipse-leshan leshan
CVE-2023-4043Parsson DoS when parsing numbers from untrusted sourcesEclipse Foundation Parsson
CVE-2023-40167Jetty accepts "+" prefixed value in Content-Lengtheclipse jetty.project
CVE-2023-36479Jetty vulnerable to errant command quoting in CGI Servleteclipse jetty.project
CVE-2023-36478HTTP/2 HPACK integer overflow and buffer allocationeclipse jetty.project
CVE-2023-3592no title heldEclipse Mosquitto
CVE-2023-26049Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jettyeclipse jetty.project
CVE-2023-26048OutOfMemoryError for large multipart without filename in Eclipse Jettyeclipse jetty.project
CVE-2023-2597no title heldEclipse OpenJ9
CVE-2023-0809no title heldEclipse Mosquitto
CVE-2022-39368Californium Failing DTLS handshakes causes Data Loss due to throttling blocking processing of recordseclipse-californium californium
CVE-2022-36022Some Deeplearning4J packages use unclaimed s3 bucket in tests and exampleseclipse deeplearning4j
CVE-2021-38443Eclipse CycloneDDS Improper Handling of Syntactically Invalid StructureEclipse CycloneDDS
CVE-2021-38441Eclipse CycloneDDS Write-what-where ConditionEclipse CycloneDDS
CVE-2021-32835Groovy Sandbox escape in Eclipse Ketieclipse keti
CVE-2021-32834Arbitrary Groovy script evaluation in Eclipse Ketieclipse keti
CVE-2020-14368no title heldn/a eclipse
CVE-2017-7650no title heldEclipse Foundation Mosquitto
CVE-2017-7649no title heldEclipse Kura Installer

189 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.