Eclipse Foundation

First CVE: Sep 11, 2017Active for: 9 years
233
CVEs Published
More CVEs Published than 81% of tracked CNAs
23.3
Avg CVEs / Year
More Avg CVEs / Year than 72% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 58% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Eclipse Foundation as a CNA, 94.4% affect products that Eclipse Foundation develops as a vendor.

94.4%
Self-reported: 220Third-party: 13

Of all the CVEs published that affect products developed by Eclipse Foundation, 79.1% are self-published by Eclipse Foundation as a CNA.

79.1%
20.9%
Self-published: 220Published by other CNAs: 58

Trends Over Time

The number and severity of CVEs published by Eclipse Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2017
8 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Eclipse Foundation as a CNA, regardless of affected vendor or product.

233 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB
Jun 9, 20215.374NOYES
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code i
Jun 25, 20219.873NOYES
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound
Oct 30, 20249.860NONO
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert
Nov 15, 20187.543NONO
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers
Jun 26, 20189.841NONO
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write
Jul 14, 20269.040NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA233 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local21 (9.0%)
Network206 (88.4%)
Unknown0 (0.0%)
Physical5 (2.1%)
Adjacent Network1 (0.4%)
Attack Complexity
Low207 (88.8%)
High26 (11.2%)
Unknown0 (0.0%)
User Interaction
None194 (83.3%)
Unknown0 (0.0%)
Required36 (15.5%)
Privileges Required
Low51 (21.9%)
High4 (1.7%)
None178 (76.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (233 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.9% of CVEs· 87th percentile
Nuclei
4 CVEs
1.7% of CVEs· 84th percentile
ExploitDB
2 CVEs
0.9% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Eclipse Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Eclipse Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs