Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Eclipse Foundation — Vulnerabilities & Security Advisories 104

Browse all 104 CVE security advisories affecting Eclipse Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Eclipse Foundation operates as a non-profit organization managing an open-source ecosystem, primarily hosting the Eclipse Integrated Development Environment (IDE) and related tooling. Its infrastructure supports a vast array of plugins and projects, creating a complex attack surface that has historically resulted in numerous security vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or insecure default configurations within specific plugins rather than the core platform itself. While the Foundation maintains rigorous governance and security advisory processes, the decentralized nature of its project portfolio means individual components may lag in patching. Notable incidents have highlighted risks associated with supply chain dependencies and outdated libraries within the broader ecosystem. Consequently, users must prioritize regular updates and strict plugin vetting to mitigate exposure to these historically common vulnerability classes.

CVE IDTitleCVSSSeverityPublished
CVE-2026-4983 Open VSX存储型XSS漏洞 — Eclipse Open VSXCWE-79 4.1 Medium2026-06-23
CVE-2026-11576 NetX Duo 未初始化内存访问漏洞 — Eclipse ThreadX - NetX DuoCWE-415 7.5 High2026-06-19
CVE-2026-44691 Eclipse Theia<1.69.0 任意命令执行漏洞 — Eclipse TheiaCWE-829--2026-06-18
CVE-2026-22551 Eclipse Theia <1.71.0信息泄露漏洞 — Eclipse TheiaCWE-201--2026-06-18
CVE-2026-46580 Eclipse Theia<1.71.0间接提示注入漏洞 — Eclipse TheiaCWE-829--2026-06-18
CVE-2026-44688 Eclipse Theia<1.71.0提示注入致数据泄露及命令执行 — Eclipse TheiaCWE-1427--2026-06-18
CVE-2026-9158 Eclipse 4diac FORTE 3.0.0-3.1.0 内存释放后使用漏洞 — Eclipse 4diacCWE-416--2026-06-18
CVE-2026-2586 Eclipse Glassfish 代码注入漏洞 — Eclipse GlassfishCWE-94 9.1 Critical2026-05-19
CVE-2026-2587 Eclipse Glassfish 安全漏洞 — Eclipse GlassfishCWE-917 9.6 Critical2026-05-19
CVE-2026-6860 Eclipse Vert.x 安全漏洞 — Eclipse Vert.x 9.1AICriticalAI2026-05-06
CVE-2026-7412 Eclipse BaSyx Java Server SDK 代码问题漏洞 — Eclipse BaSyxCWE-918 8.6 High2026-05-05
CVE-2026-7411 Eclipse BaSyx Java Server SDK 路径遍历漏洞 — Eclipse BaSyxCWE-22 10.0 Critical2026-05-05
CVE-2026-6918 Eclipse OpenJ9 缓冲区错误漏洞 — Eclipse OpenJ9CWE-125 6.5 -2026-05-05
CVE-2026-6272 KUKSA.val 访问控制错误漏洞 — Eclipse KUKSA - DatabrokerCWE-306 7.1AIHighAI2026-04-24
CVE-2026-2332 HTTP Request Smuggling via Chunked Extension Quoted-String Parsing — Eclipse JettyCWE-444 7.4 High2026-04-14
CVE-2026-5795 Eclipse Jetty 授权问题漏洞 — Eclipse JettyCWE-226 7.4 High2026-04-08
CVE-2026-24457 OpenMQ 安全漏洞 — Eclipse OpenMQCWE-22 9.1 Critical2026-03-05
CVE-2026-1605 Eclipse Jetty 安全漏洞 — Eclipse JettyCWE-400 7.5 High2026-03-05
CVE-2025-11143 Eclipse Jetty 输入验证错误漏洞 — Eclipse JettyCWE-20 3.7 Low2026-03-05
CVE-2026-22886 OpenMQ 安全漏洞 — Eclipse OpenMQCWE-1392 9.8 Critical2026-03-03
CVE-2026-1699 Eclipse Theia - Website 安全漏洞 — Eclipse Theia - WebsiteCWE-829 10.0 Critical2026-01-30
CVE-2026-1188 Eclipse OMR 安全漏洞 — Eclipse OMRCWE-131 9.8AICriticalAI2026-01-29
CVE-2026-0648 Eclipse ThreadX USBX 安全漏洞 — Eclipse ThreadXCWE-253 7.8 High2026-01-27
CVE-2025-55095 Eclipse ThreadX USBX 安全漏洞 — Eclipse ThreadX - USBXCWE-121 4.2 Medium2026-01-27
CVE-2025-55102 Eclipse ThreadX NetX Duo 安全漏洞 — Eclipse ThreadX - NetX DuoCWE-400 7.5AIHighAI2026-01-27
CVE-2025-2515 Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies — BlueChiCWE-863 7.2 High2025-12-24
CVE-2025-10543 Eclipse Paho Go MQTT v3.1 library 安全漏洞 — paho.mqtt.golang (Go MQTT v3.1 library)CWE-681 7.5AIHighAI2025-12-02
CVE-2025-12383 Race Condition allows Bypass of Trust Restrictions — JerseyCWE-362 7.4AIHighAI2025-11-18
CVE-2025-11965 Eclipse Vert.x 安全漏洞 — Vert.xCWE-552 7.5AIHighAI2025-10-22
CVE-2025-11966 Eclipse Vert.x 安全漏洞 — Vert.xCWE-79 5.4AIMediumAI2025-10-22

This page lists every published CVE security advisory associated with Eclipse Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.