eclipse

13 records · 13 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names eclipse as an affected vendor, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-10050public PoC

    In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for histori

    jetty

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-60009public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp,

    theia

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.2CVE-2026-58080public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the defaul

    milo

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-61891public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without

    theia

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-46581public PoC

    In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal requ

    mojarra

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-12609public PoC

    In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that

    theia

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-63252public PoC

    In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete c

    milo

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-62927public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it wit

    milo

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.5CVE-2026-61387public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems

    milo

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.4CVE-2026-60007public PoC

    In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted usernam

    milo

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 6.5CVE-2026-14574public PoC

    In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function

    theia

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 6.5CVE-2026-63248public PoC

    In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over Si

    milo

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 5.5CVE-2026-14304public PoC

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. I

    accessibility tools framework · michecker

    AI risk analysis on Exploit-DB.ai →