Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Eclipse Foundation — Vulnerabilities & Security Advisories 144

Browse all 144 CVE security advisories affecting Eclipse Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Eclipse Foundation operates as a non-profit organization managing an open-source ecosystem, primarily hosting the Eclipse Integrated Development Environment (IDE) and related tooling. Its infrastructure supports a vast array of plugins and projects, creating a complex attack surface that has historically resulted in numerous security vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or insecure default configurations within specific plugins rather than the core platform itself. While the Foundation maintains rigorous governance and security advisory processes, the decentralized nature of its project portfolio means individual components may lag in patching. Notable incidents have highlighted risks associated with supply chain dependencies and outdated libraries within the broader ecosystem. Consequently, users must prioritize regular updates and strict plugin vetting to mitigate exposure to these historically common vulnerability classes.

CVE ID Title CVSS Severity Published
CVE-2025-55078 Incomplete validation of kernel object pointers in system calls — ThreadX CWE-233 7.5AI High AI 2025-10-14
CVE-2025-7962 Eclipse Jakarta Mail 安全漏洞 — Jakarta Mail CWE-147 7.5 - 2025-07-21
CVE-2024-9408 Eclipse GlassFish 代码问题漏洞 — Eclipse Glassfish CWE-918 9.8 - 2025-07-16
CVE-2024-10032 Eclipse GlassFish 跨站脚本漏洞 — Eclipse Glassfish CWE-79 4.8 - 2025-07-16
CVE-2024-10031 Eclipse GlassFish 跨站脚本漏洞 — Eclipse Glassfish CWE-79 5.4 - 2025-07-16
CVE-2024-10029 Eclipse GlassFish 跨站脚本漏洞 — Eclipse Glassfish CWE-79 6.1 - 2025-07-16
CVE-2024-9343 Eclipse GlassFish 跨站脚本漏洞 — Eclipse Glassfish CWE-79 4.8 - 2025-07-16
CVE-2024-9342 Eclipse GlassFish 安全漏洞 — Eclipse Glassfish CWE-307 9.8 - 2025-07-16
CVE-2025-6705 Eclipse Open VSX 安全漏洞 — Eclipse Open VSX Registry CWE-913 9.8AI Critical AI 2025-06-27
CVE-2025-4447 Buffer Overflow in Eclipse OpenJ9 — OpenJ9 CWE-121 9.8AI Critical AI 2025-05-09
CVE-2025-1948 Eclipse Jetty HTTP clients can increase memory allocation — Jetty CWE-400 7.5 High 2025-05-08
CVE-2024-13009 Eclipse Jetty GZIP buffer release — Jetty CWE-404 7.2 High 2025-05-08
CVE-2025-2259 Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflow — ThreadX CWE-191 7.5AI High AI 2025-04-06
CVE-2025-2260 Eclipse ThreadX NetX Duo HTTP component server denial of service — ThreadX CWE-459 7.5AI High AI 2025-04-06
CVE-2025-2258 Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow — ThreadX CWE-191 7.5AI High AI 2025-04-06
CVE-2024-10838 Integer Underflow in DDS_Security_Deserialize_ methods may lead to OOB read — Eclipse Cyclone DDS CWE-191 9.1 - 2025-03-12
CVE-2025-1471 Eclipse OMR: Buffer overflow vulnerability — Eclipse OMR CWE-787 9.8 - 2025-02-21
CVE-2025-1470 Eclipse OMR: Null pointer dereference vulnerability — Eclipse OMR CWE-476 7.5 - 2025-02-21
CVE-2025-0727 Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow — ThreadX CWE-191 7.5 - 2025-02-21
CVE-2025-0728 Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow — ThreadX CWE-191 7.5 - 2025-02-21
CVE-2025-0726 Eclipse ThreadX NetX Duo HTTP server denial of service — ThreadX CWE-459 7.5 - 2025-02-21
CVE-2025-1007 Improper Authorization in /user/namespace/{namespace}/details — OpenVSX CWE-285 4.3 - 2025-02-19
CVE-2024-10917 Eclipse OpenJ9 might return an incorrect value in JNI function GetStringUTFLength — Open J9 CWE-190 3.7 Low 2024-11-11
CVE-2024-3935 Eclipse Mosquito: Double free vulnerability — mosquitto CWE-415 9.8AI Critical AI 2024-10-30
CVE-2024-10525 Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback — mosquitto CWE-122 9.8 - 2024-10-30
CVE-2024-8184 Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks — Jetty CWE-400 5.9 Medium 2024-10-14
CVE-2024-6762 Jetty PushSessionCacheFilter can cause remote DoS attacks — Jetty CWE-400 3.1 Low 2024-10-14
CVE-2024-6763 Jetty URI parsing of invalid authority — Jetty CWE-1286 3.7 Low 2024-10-14
CVE-2024-9823 Jetty DOS vulnerability on DosFilter — Jetty CWE-400 5.3 Medium 2024-10-14
CVE-2024-8376 Memory leak — Mosquitto CWE-401 9.1 - 2024-10-11

This page lists every published CVE security advisory associated with Eclipse Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.