Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Eclipse Foundation — Vulnerabilities & Security Advisories 144

Browse all 144 CVE security advisories affecting Eclipse Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Eclipse Foundation operates as a non-profit organization managing an open-source ecosystem, primarily hosting the Eclipse Integrated Development Environment (IDE) and related tooling. Its infrastructure supports a vast array of plugins and projects, creating a complex attack surface that has historically resulted in numerous security vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or insecure default configurations within specific plugins rather than the core platform itself. While the Foundation maintains rigorous governance and security advisory processes, the decentralized nature of its project portfolio means individual components may lag in patching. Notable incidents have highlighted risks associated with supply chain dependencies and outdated libraries within the broader ecosystem. Consequently, users must prioritize regular updates and strict plugin vetting to mitigate exposure to these historically common vulnerability classes.

CVE ID Title CVSS Severity Published
CVE-2026-16440 Eclipse OpenJ9≤0.60.class文件段错误漏洞 — Eclipse OpenJ9 CWE-674 5.7 Medium 2026-08-19
CVE-2026-19884 Eclipse Theia 配置错误漏洞 — Eclipse Theia CWE-829 8.4 High 2026-08-14
CVE-2026-15803 Eclipse RDF4J 输入验证错误漏洞 — Eclipse RDF4J CWE-611 8.7 High 2026-08-12
CVE-2026-12605 Eclipse GlassFish 服务端请求伪造漏洞 — Eclipse GlassFish CWE-918 9.6 Critical 2026-08-06
CVE-2026-46581 Eclipse Mojarra 路径遍历漏洞 — Eclipse Mojarra CWE-22 - - 2026-08-05
CVE-2026-61891 Eclipse Theia 信息泄露漏洞 — Eclipse Theia CWE-22 7.5 High 2026-08-05
CVE-2026-60009 Eclipse Theia 路径遍历漏洞 — Eclipse Theia CWE-352 8.8 High 2026-08-05
CVE-2026-12609 Eclipse Theia 路径遍历漏洞 — Eclipse Theia CWE-22 7.5 High 2026-08-05
CVE-2026-14574 Eclipse Theia 输入验证错误漏洞 — Eclipse Theia CWE-1321 5.7 Medium 2026-08-05
CVE-2026-14304 Eclipse Accessibility Tools Framework 输入验证错误漏洞 — Eclipse Accessibility Tools Framework (ACTF) CWE-611 4.6 Medium 2026-08-05
CVE-2026-63248 Eclipse Milo 授权问题漏洞 — Eclipse Milo CWE-862 6.9 Medium 2026-08-04
CVE-2026-58080 Eclipse Milo 授权问题漏洞 — Eclipse Milo CWE-862 8.8 High 2026-08-04
CVE-2026-63252 Eclipse Milo 资源管理错误漏洞 — Eclipse Milo CWE-401 8.7 High 2026-08-04
CVE-2026-62927 Eclipse Milo 授权问题漏洞 — Eclipse Milo CWE-863 8.7 High 2026-08-04
CVE-2026-60007 Eclipse Milo 信息泄露漏洞 — Eclipse Milo CWE-204 9.1 Critical 2026-08-04
CVE-2026-61387 Eclipse Milo 资源管理错误漏洞 — Eclipse Milo CWE-460 6.9 Medium 2026-08-04
CVE-2026-10050 Digest authentication lossy encoding — Eclipse Jetty - EE8 CWE-173 8.7 High 2026-08-04
CVE-2026-18353 Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass — Eclipse CSI - PIA CWE-918 8.8 High 2026-07-30
CVE-2026-15704 CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components — Eclipse BaSyx Go Components CWE-863 9.8 Critical 2026-07-24
CVE-2026-16441 Eclipse OpenJ9 : Method resolution default method precedence failure — OpenJ9 CWE-758 - - 2026-07-21
CVE-2026-16243 Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero — Eclipse OMR CWE-125 - - 2026-07-21
CVE-2026-16439 Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow — OpenJ9 CWE-124 - - 2026-07-21
CVE-2026-16454 Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration — eclipse-hawkbit/hawkbit CWE-284 4.3 Medium 2026-07-21
CVE-2024-7708 Eclipse Jetty 资源管理错误漏洞 — Eclipse Jetty CWE-400 7.5 High 2026-07-14
CVE-2026-8384 Eclipse jetty 授权问题漏洞 — Eclipse Jetty CWE-647 5.3 Medium 2026-07-14
CVE-2026-6790 Eclipse Jetty 输入验证错误漏洞 — Eclipse Jetty CWE-20 5.3 Medium 2026-07-14
CVE-2026-10051 Eclipse Jetty 信息泄露漏洞 — Eclipse Jetty CWE-200 - - 2026-07-14
CVE-2026-12606 Eclipse Glassfish 输入验证错误漏洞 — Eclipse GlassFish CWE-444 6.3 Medium 2026-07-14
CVE-2026-15075 Eclipse vert.x 信息泄露漏洞 — Eclipse Vert.x CWE-200 - - 2026-07-14
CVE-2026-15076 Eclipse Vert.x 输入验证错误漏洞 — Eclipse Vert.x CWE-346 - - 2026-07-14

This page lists every published CVE security advisory associated with Eclipse Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.