๐Ÿ” CVE Alert

CVE-2026-63252

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.

CWE CWE-401
Vendor eclipse foundation
Product eclipse milo
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse milo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse milo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Milo
0.6.0 โ‰ค 1.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-milo/milo/commit/459715793ec54b0f33367a14f94264500a0d872b gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/179

Credits

Abhinav Agarwal (GitHub: @abhinavagarwal07)