Vulnerabilidades en Eclipse Foundation

170 resultados
Análisis Vexday

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2026-16441MEDIUMEclipse OpenJ9 : Method resolution default method precedence failureEPSS 0.3%CVE-2026-58080HIGHIn Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely oEPSS 0.3%CVE-2026-9267MEDIUMEclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_cerEPSS 0.3%CVE-2025-55097LOWPotential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get()EPSS 0.3%CVE-2026-6272HIGHA client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStreamEPSS 0.3%CVE-2026-89321MEDIUMPublishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entryEPSS 0.3%CVE-2026-12611HIGHA client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threadsEPSS 0.3%CVE-2025-55082MEDIUMPotential out of bound read and info leak in_nx_secure_tls_psk_identity_find()EPSS 0.3%CVE-2025-55083MEDIUMBroken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()EPSS 0.3%CVE-2026-82958HIGHIn Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command byEPSS 0.2%CVE-2025-6705HIGHA vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. SpecifEPSS 0.2%CVE-2026-16439MEDIUMEclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflowEPSS 0.2%CVE-2026-18353HIGHUnauthenticated SSRF in PIA via OIDC issuer allowlist bypassEPSS 0.2%CVE-2026-6860MEDIUMA TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard nameEPSS 0.2%CVE-2026-16440MEDIUMIn Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.EPSS 0.2%CVE-2025-10543MEDIUMIn Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly EPSS 0.2%CVE-2026-82180CRITICALIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFiEPSS 0.2%CVE-2024-9343MEDIUMIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.EPSS 0.2%CVE-2026-10054HIGHIn affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shellEPSS 0.2%CVE-2025-4447HIGHBuffer Overflow in Eclipse OpenJ9EPSS 0.2%