Vulnerabilities in Eclipse Foundation

170 results
Vexday analysis

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2026-92611MEDIUMIn Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard EPSS 0.2%CVE-2025-2515HIGHBluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependenciesEPSS 0.2%CVE-2024-3933MEDIUMEclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a bufferEPSS 0.2%CVE-2024-10032MEDIUMIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.EPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2024-10029MEDIUMIn Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.EPSS 0.2%CVE-2026-15075HIGHIn Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates alEPSS 0.2%CVE-2026-15076HIGHIn versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client doesEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2025-1471HIGHEclipse OMR: Buffer overflow vulnerabilityEPSS 0.2%CVE-2026-92612LOWIn Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::asEPSS 0.2%CVE-2025-1470MEDIUMEclipse OMR: Null pointer dereference vulnerabilityEPSS 0.2%CVE-2025-55078MEDIUMIncomplete validation of kernel object pointers in system callsEPSS 0.2%CVE-2026-14304MEDIUMIn Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based applicatEPSS 0.2%CVE-2025-55079MEDIUMMissing check for thread priorityEPSS 0.2%CVE-2026-84736HIGHIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disablesEPSS 0.2%CVE-2025-55096LOWInadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get()EPSS 0.2%CVE-2024-10031MEDIUMIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the unEPSS 0.2%CVE-2025-11143LOWThe Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs EPSS 0.2%CVE-2026-63248MEDIUMIn Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can eEPSS 0.2%