In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 05 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse openj9 |
|
| Vendors & Products |
Eclipse
Eclipse openj9 |
Tue, 05 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Pre‑authentication Remote Crash of JITServer in Eclipse OpenJ9 |
Tue, 05 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published: 2026-05-05T12:29:09.667Z
Updated: 2026-05-05T13:11:47.122Z
Reserved: 2026-04-23T16:00:33.514Z
Link: CVE-2026-6918
Updated: 2026-05-05T13:11:36.933Z
Status : Analyzed
Published: 2026-05-05T13:16:30.710
Modified: 2026-05-05T20:08:58.747
Link: CVE-2026-6918
No data.
ReportizFlow