CVE-2026-63252: Eclipse Eclipse Milo vulnerability
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63252?
CVE-2026-63252 has a risk rating of 68, indicating a medium level of severity.
How do I fix CVE-2026-63252?
To address CVE-2026-63252, upgrade Eclipse Milo to version 1.1.5 or later, where this vulnerability has been patched.
What type of vulnerability is CVE-2026-63252?
CVE-2026-63252 is a memory exhaustion vulnerability that can be exploited by sending incomplete message chunks.
Who is affected by CVE-2026-63252?
Users of Eclipse Milo versions 0.6.0 through 1.1.4 are affected by CVE-2026-63252.
What is the impact of CVE-2026-63252 exploitation?
Exploiting CVE-2026-63252 can lead to exhaustion of pooled direct memory, potentially causing denial of service.