CVE Tools

Eclipse-foundation

163 CVEs tracked since 2017. Since Sep 2017, none of them reached CISA KEV.

Eclipse-foundation CVEs per month

Sep 2017 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Eclipse-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0920
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0650
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-0220
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-1020
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-0440
2021-05null or fewer
2021-06null or fewer
2021-0740
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-0730
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-0960
2023-10null or fewer
2023-1140
2023-12null or fewer
2024-01null or fewer
2024-0240
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-0950
2024-1070
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-0260
2025-03null or fewer
2025-04null or fewer
2025-0540
2025-06null or fewer
2025-0770
2025-08null or fewer
2025-09null or fewer
2025-10230
2025-11null or fewer
2025-12null or fewer
2026-0150
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-0690
2026-07210
2026-08200
2026-09200

Products

The products that kept showing up in Eclipse-foundation's monthly top three, with their CVEs summed over those months.

  1. Jetty228 months
  2. Netx Duo111 month
  3. Eclipse Theia102 months
  4. Eclipse Glassfish72 months
  5. Eclipse Milo61 month
  6. Threadx62 months
  7. Eclipse Mosquitto53 months
  8. Eclipse Aerios41 month
  9. Eclipse Ankaios41 month
  10. Eclipse Jetty41 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Eclipse-foundation.

  1. CVE-2026-90882Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data—
  2. CVE-2026-92612In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice with...—
  3. CVE-2025-12999UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with...—
  4. CVE-2026-92611In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entr...—
  5. CVE-2026-86836In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the wo...—
  6. CVE-2026-88819In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.—
  7. CVE-2026-78299In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing o...9.1
  8. CVE-2026-89321Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode...4.3
  9. CVE-2026-84197In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript...—
  10. CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and creden...—
  11. CVE-2026-12611A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsiv...—
  12. CVE-2026-19203A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP ...—
  13. CVE-2026-86590In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host...—
  14. CVE-2026-19204A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. Thi...—
  15. CVE-2026-85201In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A wor...—

The record

Peak rank
#46 in Oct 2025
Busiest month shown
Oct 2025, 23 CVEs
Months with a KEV entry
0 since Sep 2017
Monthly snapshots
21 since 2017
Eclipse-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store