๐Ÿ” CVE Alert

CVE-2026-60007

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

CWE CWE-204
Vendor eclipse foundation
Product eclipse milo
Published Aug 4, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse milo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Milo
0.6.0 โ‰ค 1.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fb gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/183

Credits

Abhinav Agarwal (GitHub: @abhinavagarwal07)