๐Ÿ” CVE Alert

CVE-2026-85201

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.

CWE CWE-789 CWE-1284
Vendor eclipse foundation
Product eclipse ankaios
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse ankaios

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse ankaios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Ankaios
0.1.0 โ‰ค 1.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/900 github.com: https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.2 github.com: https://github.com/eclipse-ankaios/ankaios/pull/791

Credits

Eclipse Foundation Security Team