PT-2026-67700 · Eclipse Foundation · Eclipse Milo
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Milo versions 0.6.0 through 1.1.4
Description
UASC server transport handlers do not release retained partial message chunks upon channel disconnection. This allows a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, which may lead to server termination.
Recommendations
Update Eclipse Milo to a version later than 1.1.4.
Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Milo