CVE-2026-63252

8.7

Eclipse Foundation · Eclipse Milo

Eclipse Milo is susceptible to a memory leak vulnerability due to improper resource management, which can lead to a denial of service condition.

Executive summary

A memory leak vulnerability in Eclipse Milo versions 0.6.0 through 1.1.4 allows unauthenticated remote attackers to cause a denial of service.

Vulnerability

The vulnerability is identified as a memory leak (CWE-401) occurring within the software, allowing an unauthenticated attacker to exhaust system resources over the network.

Business impact

Successful exploitation results in a denial of service, rendering the affected industrial automation services unavailable. Given the CVSS score of 8.7, this represents a significant risk to operational continuity, as attackers do not require authentication to trigger the resource exhaustion.

Remediation

Immediate Action: Review the provided vendor references to identify available security patches or configuration hardening steps to prevent resource exhaustion.

Proactive Monitoring: Monitor memory utilization on systems running Eclipse Milo and investigate any unexplained spikes or gradual increases in consumption that correlate with network traffic.

Compensating Controls: Implement network traffic limiting or rate limiting at the perimeter to reduce the volume of malicious requests targeting the service.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Eclipse Milo should prioritize identifying affected instances within their environment. While a specific patch version is currently being verified, administrators should apply the latest security updates provided by the Eclipse Foundation immediately upon release to mitigate the risk of service disruption.

More Eclipse Foundation CVEs