{"schema_version":1,"title":"Eclipse Foundation vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 45 vulnerabilities in Eclipse Foundation: 1 in the last 7 days and 24 in the last 90 days, 8 of them critical and 1 exploited in the wild. The most recent, CVE-2026-90882, was published on 22 September 2026. 6 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/eclipse-foundation","json_url":"https://junglewise.ai/threats/vendors/eclipse-foundation.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/eclipse-foundation","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":18,"all_time":45,"critical":8,"exploited":1,"last_7_days":1,"last_30_days":1,"last_90_days":24,"last_365_days":42},"latest":[{"cve":"CVE-2026-90882","epss":0.0044,"slug":"cve-2026-90882-the-open-vsx-org-deployment-returned-access-control-allow-origin","title":"Open VSX CORS misconfiguration with credential reflection","severity":"info","exploited":false,"published_at":"2026-09-22T10:17:10+00:00","url":"https://junglewise.ai/threats/cve-2026-90882-the-open-vsx-org-deployment-returned-access-control-allow-origin"},{"cve":"CVE-2026-18353","cvss":8.8,"slug":"cve-2026-18353-eclipse-foundation-eclipse-csi-pia-ssrf-via-oidc-issuer-allowlist","title":"Eclipse Foundation Eclipse CSI - PIA SSRF via OIDC issuer allowlist bypass","severity":"info","exploited":false,"published_at":"2026-07-30T08:16:28.887+00:00","url":"https://junglewise.ai/threats/cve-2026-18353-eclipse-foundation-eclipse-csi-pia-ssrf-via-oidc-issuer-allowlist"},{"cve":"CVE-2026-15704","cvss":9.8,"slug":"cve-2026-15704-eclipse-basyx-go-components-abac-authorization-bypass-via","title":"Eclipse BaSyx Go Components ABAC authorization bypass via trailing slash","severity":"critical","exploited":false,"published_at":"2026-07-24T09:16:24.113+00:00","url":"https://junglewise.ai/threats/cve-2026-15704-eclipse-basyx-go-components-abac-authorization-bypass-via"},{"cve":"CVE-2026-10050","cvss":4,"epss":0.0063,"slug":"cve-2026-10050-eclipse-jetty-auth-bypass-via-iso-8859-1-encoding-in-digest","title":"Eclipse Jetty auth bypass via ISO-8859-1 encoding in Digest Authentication","severity":"high","exploited":false,"published_at":"2026-07-22T22:55:18+00:00","url":"https://junglewise.ai/threats/cve-2026-10050-eclipse-jetty-auth-bypass-via-iso-8859-1-encoding-in-digest"},{"cve":"CVE-2026-16243","cvss":5.7,"slug":"cve-2026-16243-eclipse-omr-out-of-bounds-read-in-arraycmp-simd-implementation","title":"Eclipse OMR out-of-bounds read in arraycmp SIMD implementation","severity":"info","exploited":false,"published_at":"2026-07-21T18:16:56.727+00:00","url":"https://junglewise.ai/threats/cve-2026-16243-eclipse-omr-out-of-bounds-read-in-arraycmp-simd-implementation"},{"cve":"CVE-2026-16454","cvss":4.3,"slug":"cve-2026-16454-eclipse-hawkbit-privilege-escalation-in-ddi-controller","title":"Eclipse hawkBit privilege escalation in DDI Controller","severity":"medium","exploited":false,"published_at":"2026-07-21T17:17:05.887+00:00","url":"https://junglewise.ai/threats/cve-2026-16454-eclipse-hawkbit-privilege-escalation-in-ddi-controller"},{"cve":"CVE-2026-9561","cvss":8.8,"slug":"cve-2026-9561-eclipse-kura-ip-spoofing-via-x-forwarded-for-header","title":"Eclipse Kura IP spoofing via X-Forwarded-For header","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:42.18+00:00","url":"https://junglewise.ai/threats/cve-2026-9561-eclipse-kura-ip-spoofing-via-x-forwarded-for-header"},{"cve":"CVE-2026-8384","cvss":5.3,"epss":0.0033,"slug":"cve-2026-8384-eclipse-jetty-path-normalization-bypass-via-uri-path-parameters","title":"Eclipse Jetty path normalization bypass via URI path parameters","severity":"medium","exploited":false,"published_at":"2026-07-14T09:16:42.05+00:00","url":"https://junglewise.ai/threats/cve-2026-8384-eclipse-jetty-path-normalization-bypass-via-uri-path-parameters"},{"cve":"CVE-2026-6790","cvss":5.3,"epss":0.0031,"slug":"cve-2026-6790-eclipse-jetty-host-authority-and-host-header-mismatch","title":"Eclipse Jetty host authority and Host header mismatch","severity":"medium","exploited":false,"published_at":"2026-07-14T09:16:41.93+00:00","url":"https://junglewise.ai/threats/cve-2026-6790-eclipse-jetty-host-authority-and-host-header-mismatch"},{"cve":"CVE-2026-57898","cvss":9,"slug":"cve-2026-57898-eclipse-basyx-java-server-sdk-path-traversal-in-aas-thumbnail-api","title":"Eclipse BaSyx Java Server SDK path traversal in AAS thumbnail API","severity":"critical","exploited":false,"published_at":"2026-07-14T09:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-57898-eclipse-basyx-java-server-sdk-path-traversal-in-aas-thumbnail-api"},{"cve":"CVE-2026-15076","cvss":8.2,"slug":"cve-2026-15076-eclipse-vert-x-web-client-cross-domain-cookie-injection-in","title":"Eclipse Vert.x Web Client cross-domain cookie injection in WebClientSession","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:40.313+00:00","url":"https://junglewise.ai/threats/cve-2026-15076-eclipse-vert-x-web-client-cross-domain-cookie-injection-in"},{"cve":"CVE-2026-15075","cvss":8.2,"slug":"cve-2026-15075-eclipse-vert-x-sensitive-header-propagation-in-httpclient","title":"Eclipse Vert.x sensitive header propagation in HttpClient redirect handler","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:40.18+00:00","url":"https://junglewise.ai/threats/cve-2026-15075-eclipse-vert-x-sensitive-header-propagation-in-httpclient"},{"cve":"CVE-2026-13699","cvss":4.3,"slug":"cve-2026-13699-eclipse-kuksa-databroker-thread-panic-in-publishvalue-grpc","title":"Eclipse KUKSA Databroker thread panic in PublishValue gRPC handler","severity":"medium","exploited":false,"published_at":"2026-07-14T09:16:40.05+00:00","url":"https://junglewise.ai/threats/cve-2026-13699-eclipse-kuksa-databroker-thread-panic-in-publishvalue-grpc"},{"cve":"CVE-2026-12606","cvss":6.3,"slug":"cve-2026-12606-eclipse-grizzly-http-request-smuggling-in-trailer-header-parsing","title":"Eclipse Grizzly HTTP request smuggling in trailer header parsing","severity":"info","exploited":false,"published_at":"2026-07-14T09:16:39.92+00:00","url":"https://junglewise.ai/threats/cve-2026-12606-eclipse-grizzly-http-request-smuggling-in-trailer-header-parsing"},{"cve":"CVE-2026-10051","cvss":4,"epss":0.003,"slug":"cve-2026-10051-eclipse-jetty-information-leakage-via-retained-http-1-1-trailers","title":"Eclipse Jetty information leakage via retained HTTP/1.1 trailers","severity":"medium","exploited":false,"published_at":"2026-07-14T09:16:39.783+00:00","url":"https://junglewise.ai/threats/cve-2026-10051-eclipse-jetty-information-leakage-via-retained-http-1-1-trailers"},{"cve":"CVE-2024-7708","cvss":7.5,"epss":0.0044,"slug":"cve-2024-7708-eclipse-jetty-buffer-leak-in-httpconnection","title":"Eclipse Jetty buffer leak in HttpConnection","severity":"high","exploited":false,"published_at":"2026-07-14T09:16:39.453+00:00","url":"https://junglewise.ai/threats/cve-2024-7708-eclipse-jetty-buffer-leak-in-httpconnection"},{"cve":"CVE-2026-10055","cvss":8.5,"slug":"cve-2026-10055-eclipse-theia-ssrf-in-request-service-rpc","title":"Eclipse Theia SSRF in request-service RPC","severity":"high","exploited":false,"published_at":"2026-07-03T11:16:27.6+00:00","url":"https://junglewise.ai/threats/cve-2026-10055-eclipse-theia-ssrf-in-request-service-rpc"},{"cve":"CVE-2026-10054","cvss":8.8,"slug":"cve-2026-10054-eclipse-theia-remote-command-execution-via-cross-origin-websocket","title":"Eclipse Theia remote command execution via cross-origin WebSocket access","severity":"high","exploited":false,"published_at":"2026-07-03T11:16:26.847+00:00","url":"https://junglewise.ai/threats/cve-2026-10054-eclipse-theia-remote-command-execution-via-cross-origin-websocket"},{"cve":"CVE-2026-58465","cvss":7.5,"slug":"cve-2026-58465-eclipse-wakaama-unbounded-memory-allocation-in-coap-block1","title":"Eclipse Wakaama unbounded memory allocation in CoAP Block1 handler","severity":"high","exploited":false,"published_at":"2026-07-02T19:16:59.993+00:00","url":"https://junglewise.ai/threats/cve-2026-58465-eclipse-wakaama-unbounded-memory-allocation-in-coap-block1"},{"cve":"CVE-2026-14336","cvss":8.2,"slug":"cve-2026-14336-eclipse-csi-pia-ssrf-and-auth-bypass-via-oidc-issuer-allowlist","title":"Eclipse CSI - PIA SSRF and auth bypass via OIDC issuer allowlist prefix check","severity":"high","exploited":false,"published_at":"2026-07-02T10:16:28.487+00:00","url":"https://junglewise.ai/threats/cve-2026-14336-eclipse-csi-pia-ssrf-and-auth-bypass-via-oidc-issuer-allowlist"},{"cve":"CVE-2026-9563","cvss":7.5,"slug":"cve-2026-9563-eclipse-parsson-denial-of-service-via-uncontrolled-json-parsing","title":"Eclipse Parsson denial of service via uncontrolled JSON parsing","severity":"high","exploited":false,"published_at":"2026-07-02T09:16:19.247+00:00","url":"https://junglewise.ai/threats/cve-2026-9563-eclipse-parsson-denial-of-service-via-uncontrolled-json-parsing"},{"cve":"CVE-2026-13323","cvss":4.1,"slug":"cve-2026-13323-eclipse-open-vsx-stored-xss-in-unpkg-endpoint","title":"Eclipse Open VSX stored XSS in unpkg endpoint","severity":"medium","exploited":false,"published_at":"2026-07-01T12:16:38.117+00:00","url":"https://junglewise.ai/threats/cve-2026-13323-eclipse-open-vsx-stored-xss-in-unpkg-endpoint"},{"cve":"CVE-2026-12616","cvss":6.9,"slug":"cve-2026-12616-eclipse-csi-pia-log-injection-in-v1-upload-sbom","title":"Eclipse CSI - PIA log injection in /v1/upload/sbom","severity":"info","exploited":false,"published_at":"2026-06-29T14:16:41.317+00:00","url":"https://junglewise.ai/threats/cve-2026-12616-eclipse-csi-pia-log-injection-in-v1-upload-sbom"},{"cve":"CVE-2026-9267","cvss":6.9,"slug":"cve-2026-9267-eclipse-tinydtls-out-of-bounds-read-in-check-server-certificate","title":"Eclipse tinydtls out-of-bounds read in check_server_certificate","severity":"info","exploited":false,"published_at":"2026-06-29T09:16:31.75+00:00","url":"https://junglewise.ai/threats/cve-2026-9267-eclipse-tinydtls-out-of-bounds-read-in-check-server-certificate"},{"cve":"CVE-2026-4983","cvss":4.1,"slug":"cve-2026-4983-eclipse-open-vsx-stored-xss-in-extension-icons","title":"Eclipse Open VSX stored XSS in extension icons","severity":"medium","exploited":false,"published_at":"2026-06-23T12:16:26.537+00:00","url":"https://junglewise.ai/threats/cve-2026-4983-eclipse-open-vsx-stored-xss-in-extension-icons"}],"vendor":{"hub":true,"name":"Eclipse Foundation","slug":"eclipse-foundation","homepage":"https://www.eclipse.org/","description":"The Eclipse Foundation is a non-profit corporation that provides a governance model and infrastructure for open-source software development projects.","url":"https://junglewise.ai/threats/vendors/eclipse-foundation"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":10},{"week":"2026-07-20","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2023-44487","cvss":5.3,"epss":1,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"Multiple Vendors HTTP/2 denial of service via Rapid Reset attack","severity":"critical","exploited":true,"published_at":"2023-10-10T21:28:24+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-2026-7411","cvss":10,"epss":0.0152,"slug":"cve-2026-7411-eclipse-basyx-java-server-sdk-path-traversal-in-submodel-http-api","title":"Eclipse BaSyx Java Server SDK path traversal in Submodel HTTP API","severity":"critical","exploited":false,"published_at":"2026-05-05T18:33:26+00:00","url":"https://junglewise.ai/threats/cve-2026-7411-eclipse-basyx-java-server-sdk-path-traversal-in-submodel-http-api"},{"cve":"CVE-2025-67109","cvss":10,"epss":0.003,"slug":"cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in","title":"Eclipse Cyclone DDS certificate expiration bypass in authentication plugin","severity":"critical","exploited":false,"published_at":"2025-12-23T16:16:23.057+00:00","url":"https://junglewise.ai/threats/cve-2025-67109-eclipse-cyclone-dds-certificate-expiration-bypass-in"},{"cve":"CVE-2024-9342","cvss":9.8,"epss":0.0041,"slug":"cve-2024-9342-eclipse-glassfish-improper-restriction-of-login-attempts","title":"Eclipse GlassFish improper restriction of login attempts","severity":"critical","exploited":false,"published_at":"2025-07-16T11:15:23.727+00:00","url":"https://junglewise.ai/threats/cve-2024-9342-eclipse-glassfish-improper-restriction-of-login-attempts"},{"cve":"CVE-2026-15704","cvss":9.8,"slug":"cve-2026-15704-eclipse-basyx-go-components-abac-authorization-bypass-via","title":"Eclipse BaSyx Go Components ABAC authorization bypass via trailing slash","severity":"critical","exploited":false,"published_at":"2026-07-24T09:16:24.113+00:00","url":"https://junglewise.ai/threats/cve-2026-15704-eclipse-basyx-go-components-abac-authorization-bypass-via"},{"cve":"CVE-2026-2587","cvss":9.6,"epss":0.0067,"slug":"cve-2026-2587-eclipse-glassfish-el-injection-in-gadget-handler","title":"Eclipse GlassFish EL injection in gadget handler","severity":"critical","exploited":false,"published_at":"2026-05-19T15:16:28.577+00:00","url":"https://junglewise.ai/threats/cve-2026-2587-eclipse-glassfish-el-injection-in-gadget-handler"},{"cve":"CVE-2026-2586","cvss":9.1,"epss":0.0083,"slug":"cve-2026-2586-eclipse-glassfish-rce-via-el-injection-in-administration-console","title":"Eclipse GlassFish RCE via EL Injection in Administration Console","severity":"critical","exploited":false,"published_at":"2026-05-19T15:16:28.413+00:00","url":"https://junglewise.ai/threats/cve-2026-2586-eclipse-glassfish-rce-via-el-injection-in-administration-console"},{"cve":"CVE-2026-57898","cvss":9,"slug":"cve-2026-57898-eclipse-basyx-java-server-sdk-path-traversal-in-aas-thumbnail-api","title":"Eclipse BaSyx Java Server SDK path traversal in AAS thumbnail API","severity":"critical","exploited":false,"published_at":"2026-07-14T09:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-57898-eclipse-basyx-java-server-sdk-path-traversal-in-aas-thumbnail-api"},{"cve":"CVE-2026-10054","cvss":8.8,"slug":"cve-2026-10054-eclipse-theia-remote-command-execution-via-cross-origin-websocket","title":"Eclipse Theia remote command execution via cross-origin WebSocket access","severity":"high","exploited":false,"published_at":"2026-07-03T11:16:26.847+00:00","url":"https://junglewise.ai/threats/cve-2026-10054-eclipse-theia-remote-command-execution-via-cross-origin-websocket"},{"cve":"CVE-2026-7412","cvss":8.6,"epss":0.0055,"slug":"cve-2026-7412-eclipse-basyx-java-server-sdk-ssrf-in-operation-delegation","title":"Eclipse BaSyx Java Server SDK SSRF in Operation Delegation","severity":"high","exploited":false,"published_at":"2026-05-05T16:16:18.48+00:00","url":"https://junglewise.ai/threats/cve-2026-7412-eclipse-basyx-java-server-sdk-ssrf-in-operation-delegation"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Eclipse Foundation Jetty","slug":"jetty","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jetty"},{"name":"Eclipse Foundation Theia","slug":"theia","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/theia"},{"name":"Eclipse Foundation GlassFish","slug":"glassfish","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/glassfish"},{"name":"Eclipse Foundation BaSyx Java Server SDK","slug":"basyx-java-server-sdk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/basyx-java-server-sdk"},{"name":"Eclipse Foundation CSI - PIA","slug":"csi-pia","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/csi-pia"},{"name":"Eclipse Foundation Open VSX","slug":"open-vsx","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/open-vsx"}]}