Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Eclipse Foundation — Vulnerabilities & Security Advisories 143

Browse all 143 CVE security advisories affecting Eclipse Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Eclipse Foundation operates as a non-profit organization managing an open-source ecosystem, primarily hosting the Eclipse Integrated Development Environment (IDE) and related tooling. Its infrastructure supports a vast array of plugins and projects, creating a complex attack surface that has historically resulted in numerous security vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or insecure default configurations within specific plugins rather than the core platform itself. While the Foundation maintains rigorous governance and security advisory processes, the decentralized nature of its project portfolio means individual components may lag in patching. Notable incidents have highlighted risks associated with supply chain dependencies and outdated libraries within the broader ecosystem. Consequently, users must prioritize regular updates and strict plugin vetting to mitigate exposure to these historically common vulnerability classes.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1188 Eclipse OMR 安全漏洞 — Eclipse OMRCWE-131 9.8AICriticalAI2026-01-29
CVE-2026-0648 Eclipse ThreadX USBX 安全漏洞 — Eclipse ThreadXCWE-253 7.8 High2026-01-27
CVE-2025-55095 Eclipse ThreadX USBX 安全漏洞 — Eclipse ThreadX - USBXCWE-121 4.2 Medium2026-01-27
CVE-2025-55102 Eclipse ThreadX NetX Duo 安全漏洞 — Eclipse ThreadX - NetX DuoCWE-400 7.5AIHighAI2026-01-27
CVE-2025-2515 Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies — BlueChiCWE-863 7.2 High2025-12-24
CVE-2025-10543 Eclipse Paho Go MQTT v3.1 library 安全漏洞 — paho.mqtt.golang (Go MQTT v3.1 library)CWE-681 7.5AIHighAI2025-12-02
CVE-2025-12383 Race Condition allows Bypass of Trust Restrictions — JerseyCWE-362 7.4AIHighAI2025-11-18
CVE-2025-11965 Eclipse Vert.x 安全漏洞 — Vert.xCWE-552 7.5AIHighAI2025-10-22
CVE-2025-11966 Eclipse Vert.x 安全漏洞 — Vert.xCWE-79 5.4AIMediumAI2025-10-22
CVE-2025-55086 Eclipse ThreadX NetX Duo 安全漏洞 — NextX DuoCWE-1285 9.1AICriticalAI2025-10-20
CVE-2025-55085 Web http client: Unchecked Server-Side Malicious Packet Issue — NetX DuoCWE-125 9.8AICriticalAI2025-10-17
CVE-2025-55087 Eclipse ThreadX NetX Duo 安全漏洞 — NextX DuoCWE-1285 7.1AIHighAI2025-10-17
CVE-2025-55100 Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func() — USBXCWE-125 8.2AIHighAI2025-10-17
CVE-2025-55099 Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate() — USBXCWE-125 8.2AIHighAI2025-10-17
CVE-2025-55098 Potential out-of-bounds read in _ux_host_class_audio_device_type_get() — USBXCWE-125 8.2AIHighAI2025-10-17
CVE-2025-55097 Potential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get() — USBXCWE-125 8.2AIHighAI2025-10-17
CVE-2025-55096 Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get() — NetX DuoCWE-191 8.2AIHighAI2025-10-17
CVE-2025-55094 Potential out-of-bounds read in _nx_icmpv6_validate_options() — NetX DuoCWE-125 5.3AIMediumAI2025-10-17
CVE-2025-55093 Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages — NetX DuoCWE-126 9.8AICriticalAI2025-10-17
CVE-2025-55092 Potential out of bound read in _nx_ipv4_option_process() — NetX DuoCWE-125 5.3AIMediumAI2025-10-17
CVE-2025-55091 Potential out of bound read in _nx_ip_packet_receive() — NetX DuoCWE-125 8.2AIHighAI2025-10-16
CVE-2025-55090 Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo — NetX DuoCWE-125 5.3AIMediumAI2025-10-16
CVE-2025-55089 Eclipse ThreadX FileX RAM disk driver buffer overflow — FileXCWE-119 9.1AICriticalAI2025-10-16
CVE-2025-55084 Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension() — NetX DuoCWE-126 8.8AIHighAI2025-10-16
CVE-2025-55083 Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension() — NetX DuoCWE-126 5.3AIMediumAI2025-10-15
CVE-2025-55082 Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find() — NetX DuoCWE-125 8.2AIHighAI2025-10-15
CVE-2025-55081 Potential out of bound read in _nx_secure_tls_process_clienthello() — NetX DuoCWE-126 8.2AIHighAI2025-10-15
CVE-2025-55080 Improper Parameter Check in ThreadX Syscall Implementation — ThreadXCWE-233 9.1AICriticalAI2025-10-15
CVE-2025-55079 Missing check for thread priority — ThreadXCWE-770 7.5AIHighAI2025-10-15
CVE-2025-55078 Incomplete validation of kernel object pointers in system calls — ThreadXCWE-233 7.5AIHighAI2025-10-14

This page lists every published CVE security advisory associated with Eclipse Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.