Eclipse Foundation
First CVE: Sep 11, 2017Active for: 9 years
233
CVEs Published
More CVEs Published than 81% of tracked CNAs
23.3
Avg CVEs / Year
More Avg CVEs / Year than 72% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 58% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Eclipse Foundation as a CNA, 94.4% affect products that Eclipse Foundation develops as a vendor.
94.4%
Self-reported: 220Third-party: 13
Of all the CVEs published that affect products developed by Eclipse Foundation, 79.1% are self-published by Eclipse Foundation as a CNA.
79.1%
20.9%
Self-published: 220Published by other CNAs: 58
Trends Over Time
The number and severity of CVEs published by Eclipse Foundation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2017
8 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Eclipse Foundation as a CNA, regardless of affected vendor or product.
233 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2021-28169MEDIUM For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB | Jun 9, 2021 | 5.3 | 74 | NO | YES |
CVE-2021-34427CRITICAL In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code i | Jun 25, 2021 | 9.8 | 73 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2024-10525CRITICAL In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound | Oct 30, 2024 | 9.8 | 60 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
CVE-2018-12543HIGH In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert | Nov 15, 2018 | 7.5 | 43 | NO | NO |
CVE-2017-7658CRITICAL In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers | Jun 26, 2018 | 9.8 | 41 | NO | NO |
CVE-2026-57898CRITICAL In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write | Jul 14, 2026 | 9.0 | 40 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA233 CVEs
37%
44%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (9.0%)
Network206 (88.4%)
Unknown0 (0.0%)
Physical5 (2.1%)
Adjacent Network1 (0.4%)
Attack Complexity
Low207 (88.8%)
High26 (11.2%)
Unknown0 (0.0%)
User Interaction
None194 (83.3%)
Unknown0 (0.0%)
Required36 (15.5%)
Privileges Required
Low51 (21.9%)
High4 (1.7%)
None178 (76.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (233 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.9% of CVEs· 87th percentile
Nuclei
4 CVEs
1.7% of CVEs· 84th percentile
ExploitDB
2 CVEs
0.9% of CVEs· 81st percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Eclipse Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Eclipse Foundation as a CNA — matched by CVE ID, not by organization name.