PT-2026-67697 · Eclipse Foundation · Eclipse Milo

·

CVE-2026-61387

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Milo versions 1.0.0 through 1.1.4
Description Monitored-item quota accounting is not exception-safe, meaning that if item creation fails due to an unchecked error, the server-global reservation is not restored. An unauthenticated remote client can trigger a StackOverflowError during decoding by using deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter. This allows the attacker to exhaust the finite global monitored-item quota, preventing all clients from creating new monitored items until the server is restarted. Existing monitored items and other server functions are not affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61387

Affected Products

Eclipse Milo