Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eclipse Foundation

First CVE: Dec 31, 2009Active for: 17 yearsTotal CVEs: 278
61.2
VTI Score
TOP TARGET

The Eclipse Foundation maintains a broadly represented portfolio spanning web servers, embedded messaging, virtual machines, and real-time operating-system components, creating a diverse attack surface across both cloud infrastructure and embedded deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though public exploit availability and confirmed in-the-wild exploitation remain limited relative to the disclosure volume. The exposure recurs across flagship products such as Jetty, Mosquitto, OpenJ9, ThreadX NetX Duo, and ThreadX USBX through weakness classes including out-of-bounds reads, cross-site scripting, improper input validation, and uncontrolled resource consumption, reflecting the memory-safety and input-handling demands of network-exposed and embedded software. Defenders should prioritize vulnerability monitoring for Foundation projects embedded in production infrastructure, particularly where internet-facing or resource-constrained deployments are involved; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
278
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Eclipse Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2009
16 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Self-Reporting Analysis

Of all the CVEs published by Eclipse Foundation as a CNA, 94.0% affect products that Eclipse Foundation develops as a vendor.

94.0%
Self-reported: 220 (94.0%)
Third-party: 14 (6.0%)

Of all the CVEs published that affect products developed by Eclipse Foundation, 79.1% are self-published by Eclipse Foundation as a CNA.

79.1%
20.9%
Self-published: 220 (79.1%)
Other CNAs: 58 (20.9%)

Products(69 total)

Top CVEs

Signals from CVEs in this vendor scope (278 CVEs).

278 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2021-34429MEDIUM
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
CVE-2021-28164MEDIUM
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
CVE-2015-2080HIGH
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP he
Oct 7, 20167.578NOYES
CVE-2014-9390CRITICAL
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode
Feb 12, 20209.876NOYES
CVE-2021-28169MEDIUM
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB
Jun 9, 20215.374NOYES
CVE-2021-34427CRITICAL
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code i
Jun 25, 20219.873NOYES
CVE-2020-27223MEDIUM
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
CVE-2024-10525CRITICAL
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound
Oct 30, 20249.860NONO
CVE-2021-28165HIGH
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
View all 278 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products278 CVEs
36%
41%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (8.3%)
Network245 (88.1%)
Unknown3 (1.1%)
Physical5 (1.8%)
Adjacent Network2 (0.7%)
Attack Complexity
Low249 (89.6%)
High26 (9.4%)
Unknown3 (1.1%)
User Interaction
None233 (83.8%)
Unknown3 (1.1%)
Required40 (14.4%)
Privileges Required
Low56 (20.1%)
High5 (1.8%)
None214 (77.0%)
Unknown3 (1.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (278 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 99th percentile
Metasploit
3 CVEs
1.1% of CVEs· 97th percentile
Nuclei
6 CVEs
2.2% of CVEs· 95th percentile
ExploitDB
7 CVEs
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eclipse Foundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eclipse Foundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eclipse Foundation's Products

View all 7 CNAs →

Top CWEs