The Eclipse Foundation maintains a broadly represented portfolio spanning web servers, embedded messaging, virtual machines, and real-time operating-system components, creating a diverse attack surface across both cloud infrastructure and embedded deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though public exploit availability and confirmed in-the-wild exploitation remain limited relative to the disclosure volume. The exposure recurs across flagship products such as Jetty, Mosquitto, OpenJ9, ThreadX NetX Duo, and ThreadX USBX through weakness classes including out-of-bounds reads, cross-site scripting, improper input validation, and uncontrolled resource consumption, reflecting the memory-safety and input-handling demands of network-exposed and embedded software. Defenders should prioritize vulnerability monitoring for Foundation projects embedded in production infrastructure, particularly where internet-facing or resource-constrained deployments are involved; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eclipse Foundation over time
Of all the CVEs published by Eclipse Foundation as a CNA, 94.0% affect products that Eclipse Foundation develops as a vendor.
Of all the CVEs published that affect products developed by Eclipse Foundation, 79.1% are self-published by Eclipse Foundation as a CNA.
Signals from CVEs in this vendor scope (278 CVEs).
278 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2015-2080HIGH The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP he | Oct 7, 2016 | 7.5 | 78 | NO | YES |
CVE-2014-9390CRITICAL Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode | Feb 12, 2020 | 9.8 | 76 | NO | YES |
CVE-2021-28169MEDIUM For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB | Jun 9, 2021 | 5.3 | 74 | NO | YES |
CVE-2021-34427CRITICAL In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code i | Jun 25, 2021 | 9.8 | 73 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2024-10525CRITICAL In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bound | Oct 30, 2024 | 9.8 | 60 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
Signals from CVEs in this vendor scope (278 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eclipse Foundation.
Media articles that mention a CVE ID that affects a product developed by Eclipse Foundation — matched by CVE ID, not by vendor name.