๐Ÿ” CVE Alert

CVE-2026-6918

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

CWE CWE-125
Vendor eclipse foundation
Product eclipse openj9
Published May 5, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse openj9

Be the first to know when new high vulnerabilities affecting eclipse foundation eclipse openj9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse OpenJ9
0.21 < 0.59

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969r github.com: https://github.com/eclipse-openj9/openj9/pull/23793 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-6918 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2466741 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6918.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:22328

Credits

Sebastian Josue Alba Vives