CVE-2026-63252

Eclipse Foundation · Eclipse Milo

Eclipse Milo is susceptible to a memory leak vulnerability due to improper resource management, which can lead to a denial of service condition.

Executive summary

A memory leak vulnerability in Eclipse Milo versions 0.6.0 through 1.1.4 allows unauthenticated remote attackers to cause a denial of service.

Vulnerability

The vulnerability is identified as a memory leak (CWE-401) occurring within the software, allowing an unauthenticated attacker to exhaust system resources over the network.

Business impact

Successful exploitation results in a denial of service, rendering the affected industrial automation services unavailable. Given the CVSS score of 8.7, this represents a significant risk to operational continuity, as attackers do not require authentication to trigger the resource exhaustion.

Remediation

Immediate Action: Review the provided vendor references to identify available security patches or configuration hardening steps to prevent resource exhaustion.

Proactive Monitoring: Monitor memory utilization on systems running Eclipse Milo and investigate any unexplained spikes or gradual increases in consumption that correlate with network traffic.

Compensating Controls: Implement network traffic limiting or rate limiting at the perimeter to reduce the volume of malicious requests targeting the service.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Eclipse Milo should prioritize identifying affected instances within their environment. While a specific patch version is currently being verified, administrators should apply the latest security updates provided by the Eclipse Foundation immediately upon release to mitigate the risk of service disruption.