Eclipse-foundation
163 CVEs tracked since 2017. Since Sep 2017, none of them reached CISA KEV.
Eclipse-foundation CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-09 | 2 | 0 |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | 5 | 0 |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | 2 | 0 |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | 2 | 0 |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | null or fewer | |
| 2020-09 | null or fewer | |
| 2020-10 | null or fewer | |
| 2020-11 | null or fewer | |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | 4 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | 4 | 0 |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | 3 | 0 |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | 6 | 0 |
| 2023-10 | null or fewer | |
| 2023-11 | 4 | 0 |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | 4 | 0 |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | 5 | 0 |
| 2024-10 | 7 | 0 |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | 6 | 0 |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | 4 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | 7 | 0 |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | 23 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | 5 | 0 |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | 9 | 0 |
| 2026-07 | 21 | 0 |
| 2026-08 | 20 | 0 |
| 2026-09 | 20 | 0 |
Products
The products that kept showing up in Eclipse-foundation's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Eclipse-foundation.
- CVE-2026-90882Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data—
- CVE-2026-92612In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice with...—
- CVE-2025-12999UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with...—
- CVE-2026-92611In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entr...—
- CVE-2026-86836In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the wo...—
- CVE-2026-88819In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.—
- CVE-2026-78299In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing o...9.1
- CVE-2026-89321Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode...4.3
- CVE-2026-84197In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript...—
- CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and creden...—
- CVE-2026-12611A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsiv...—
- CVE-2026-19203A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP ...—
- CVE-2026-86590In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host...—
- CVE-2026-19204A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. Thi...—
- CVE-2026-85201In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A wor...—
The record
- Peak rank
- #46 in Oct 2025
- Busiest month shown
- Oct 2025, 23 CVEs
- Months with a KEV entry
- 0 since Sep 2017
- Monthly snapshots
- 21 since 2017