Vulnerabilities in Eclipse Foundation

170 results
Vexday analysis

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2026-82217HIGHIn Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContentEPSS 0.4%CVE-2024-9202MEDIUMEDC DataSetResolver policy filtering missingEPSS 0.4%CVE-2026-18918CRITICALOAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed defaultEPSS 0.4%CVE-2026-15704CRITICALCWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go ComponentsEPSS 0.4%CVE-2026-79653MEDIUMIn Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enaEPSS 0.4%CVE-2026-86590MEDIUMIn Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied EPSS 0.4%CVE-2025-55091MEDIUMPotential out of bound read in _nx_ip_packet_receive()EPSS 0.4%CVE-2025-55081MEDIUMPotential out of bound read in _nx_secure_tls_process_clienthello()EPSS 0.4%CVE-2025-55090MEDIUMPotential out of bound read issue in _nx_ipv4_packet_receive() in NetX DuoEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-16243MEDIUMEclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zeroEPSS 0.4%CVE-2026-16454MEDIUMPrivilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware ExfiltrationEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2026-78299CRITICALIn Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract fEPSS 0.3%CVE-2026-61387MEDIUMIn Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an uncheckeEPSS 0.3%CVE-2026-15803HIGHIn Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-baseEPSS 0.3%CVE-2024-2214HIGHMissing array size check in _Mtxinit() in the Xtensa portEPSS 0.3%CVE-2025-55084MEDIUMOut of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()EPSS 0.3%CVE-2026-13323MEDIUMIn Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a CoEPSS 0.3%CVE-2025-55092MEDIUMPotential out of bound read in _nx_ipv4_option_process()EPSS 0.3%