Vendor
Eclipse Foundation vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 45 vulnerabilities in Eclipse Foundation: 1 in the last 7 days and 24 in the last 90 days, 8 of them critical and 1 exploited in the wild. The most recent, CVE-2026-90882, was published on 22 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 24
- Critical, all time
- 8
- Exploited in the wild
- 1
About Eclipse Foundation
The Eclipse Foundation is a non-profit corporation that provides a governance model and infrastructure for open-source software development projects.
Eclipse Foundation technologies
Latest Eclipse Foundation vulnerabilities
- CVE-2026-90882: Open VSX CORS misconfiguration with credential reflectioninfoEPSS 0.4%
- CVE-2026-18353: Eclipse Foundation Eclipse CSI - PIA SSRF via OIDC issuer allowlist bypassinfoCVSS 8.8
- CVE-2026-15704: Eclipse BaSyx Go Components ABAC authorization bypass via trailing slashcriticalCVSS 9.8
- CVE-2026-10050: Eclipse Jetty auth bypass via ISO-8859-1 encoding in Digest AuthenticationhighCVSS 4EPSS 0.6%
- CVE-2026-16243: Eclipse OMR out-of-bounds read in arraycmp SIMD implementationinfoCVSS 5.7
- CVE-2026-16454: Eclipse hawkBit privilege escalation in DDI ControllermediumCVSS 4.3
- CVE-2026-9561: Eclipse Kura IP spoofing via X-Forwarded-For headerinfoCVSS 8.8
- CVE-2026-8384: Eclipse Jetty path normalization bypass via URI path parametersmediumCVSS 5.3EPSS 0.3%
- CVE-2026-6790: Eclipse Jetty host authority and Host header mismatchmediumCVSS 5.3EPSS 0.3%
- CVE-2026-57898: Eclipse BaSyx Java Server SDK path traversal in AAS thumbnail APIcriticalCVSS 9
- CVE-2026-15076: Eclipse Vert.x Web Client cross-domain cookie injection in WebClientSessioninfoCVSS 8.2
- CVE-2026-15075: Eclipse Vert.x sensitive header propagation in HttpClient redirect handlerinfoCVSS 8.2
- CVE-2026-13699: Eclipse KUKSA Databroker thread panic in PublishValue gRPC handlermediumCVSS 4.3
- CVE-2026-12606: Eclipse Grizzly HTTP request smuggling in trailer header parsinginfoCVSS 6.3
- CVE-2026-10051: Eclipse Jetty information leakage via retained HTTP/1.1 trailersmediumCVSS 4EPSS 0.3%
- CVE-2024-7708: Eclipse Jetty buffer leak in HttpConnectionhighCVSS 7.5EPSS 0.4%
- CVE-2026-10055: Eclipse Theia SSRF in request-service RPChighCVSS 8.5
- CVE-2026-10054: Eclipse Theia remote command execution via cross-origin WebSocket accesshighCVSS 8.8
- CVE-2026-58465: Eclipse Wakaama unbounded memory allocation in CoAP Block1 handlerhighCVSS 7.5
- CVE-2026-14336: Eclipse CSI - PIA SSRF and auth bypass via OIDC issuer allowlist prefix checkhighCVSS 8.2
- CVE-2026-9563: Eclipse Parsson denial of service via uncontrolled JSON parsinghighCVSS 7.5
- CVE-2026-13323: Eclipse Open VSX stored XSS in unpkg endpointmediumCVSS 4.1
- CVE-2026-12616: Eclipse CSI - PIA log injection in /v1/upload/sbominfoCVSS 6.9
- CVE-2026-9267: Eclipse tinydtls out-of-bounds read in check_server_certificateinfoCVSS 6.9
- CVE-2026-4983: Eclipse Open VSX stored XSS in extension iconsmediumCVSS 4.1
Most severe Eclipse Foundation vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-44487: Multiple Vendors HTTP/2 denial of service via Rapid Reset attackcriticalexploited in the wildCVSS 5.3EPSS 100.0%
- CVE-2026-7411: Eclipse BaSyx Java Server SDK path traversal in Submodel HTTP APIcriticalCVSS 10EPSS 1.5%
- CVE-2025-67109: Eclipse Cyclone DDS certificate expiration bypass in authentication plugincriticalCVSS 10EPSS 0.3%
- CVE-2024-9342: Eclipse GlassFish improper restriction of login attemptscriticalCVSS 9.8EPSS 0.4%
- CVE-2026-15704: Eclipse BaSyx Go Components ABAC authorization bypass via trailing slashcriticalCVSS 9.8
- CVE-2026-2587: Eclipse GlassFish EL injection in gadget handlercriticalCVSS 9.6EPSS 0.7%
- CVE-2026-2586: Eclipse GlassFish RCE via EL Injection in Administration ConsolecriticalCVSS 9.1EPSS 0.8%
- CVE-2026-57898: Eclipse BaSyx Java Server SDK path traversal in AAS thumbnail APIcriticalCVSS 9
- CVE-2026-10054: Eclipse Theia remote command execution via cross-origin WebSocket accesshighCVSS 8.8
- CVE-2026-7412: Eclipse BaSyx Java Server SDK SSRF in Operation DelegationhighCVSS 8.6EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 8 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 10 | 1 | |
| 20 Jul 2026 | 4 | 1 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/eclipse-foundation.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Eclipse Foundation vulnerabilities", https://junglewise.ai/threats/vendors/eclipse-foundation, 26 September 2026.