eclipse
28 known vulnerabilities affecting eclipse products.
Products
milo 6
jetty 5
glassfish 4
theia 4
openj9 2
openmq 1
mojarra 1
omr 1
grizzly 1
hawkbit 1
kura 1
accessibility_tools_framework 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-44487 | Act now | 100.0% | 7.5 | ● | The HTTP/2 protocol allows a denial of service (server resource consumption) bec… |
| CVE-2026-2586 | High | 0.8% | 9.1 | An authenticated Remote Code Execution (RCE) vulnerability was identified in Gla… | |
| CVE-2026-2587 | High | 0.6% | 9.6 | A critical Remote Code Execution (RCE) vulnerability was identified in the serve… | |
| CVE-2026-10050 | High | 0.5% | 9.1 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-… | |
| CVE-2026-12605 | High | 0.3% | 9.6 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet… | |
| CVE-2026-2332 | Medium | 1.3% | 7.4 | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when ch… | |
| CVE-2026-1605 | Medium | 0.7% | 7.5 | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler e… | |
| CVE-2026-24457 | Medium | 0.6% | 9.1 | An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0… | |
| CVE-2026-5795 | Medium | 0.5% | 7.4 | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication chec… | |
| CVE-2026-61891 | Medium | 0.5% | 7.5 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` ba… | |
| CVE-2026-46581 | Medium | 0.4% | 7.5 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFac… | |
| CVE-2026-63252 | Medium | 0.4% | 7.5 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fai… | |
| CVE-2026-12609 | Medium | 0.4% | 7.5 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plug… | |
| CVE-2026-60007 | Medium | 0.4% | 7.4 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns … | |
| CVE-2026-60009 | Medium | 0.4% | 8.8 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` ba… | |
| CVE-2026-16243 | Medium | 0.4% | 7.5 | In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P… | |
| CVE-2026-61387 | Medium | 0.3% | 7.5 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is… | |
| CVE-2026-62927 | Medium | 0.3% | 7.5 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the or… | |
| CVE-2026-16441 | Medium | 0.3% | 9.6 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previo… | |
| CVE-2026-58080 | Medium | 0.3% | 8.2 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails t… | |
| CVE-2026-16439 | Medium | 0.2% | 9.1 | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments c… | |
| CVE-2026-9561 | Medium | 0.2% | 8.2 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For H… | |
| CVE-2022-2712 | Low | 0.9% | 6.5 | In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relati… | |
| CVE-2026-16454 | Low | 0.4% | 4.3 | In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerabilit… | |
| CVE-2026-14574 | Low | 0.3% | 6.5 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUt… | |
| CVE-2026-12606 | Low | 0.3% | 5.3 | Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer sect… | |
| CVE-2026-14304 | Low | 0.2% | 5.5 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including … | |
| CVE-2026-63248 | Low | 0.2% | 6.5 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do… |