Skip to content
COOEY

FAIL › dossier

eclipse

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2026-06-18 CVE-2026-9158 critical In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
2026-04-14 CVE-2026-2332 high In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term
2026-08-04 CVE-2026-10050 critical CVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-
2026-07-21 CVE-2026-16439 critical CVE-2026-16439: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments c
2026-07-21 CVE-2026-16441 critical CVE-2026-16441: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previo
2026-03-05 CVE-2026-24457 critical CVE-2026-24457: An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0