Known Vulnerabilities for Eclipse CSI - PIA by Eclipse Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Eclipse CSI - PIA" by "Eclipse Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75058 json | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-63252 json | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks ... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-63248 json | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymo... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-62927 json | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers ... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-61891 json | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-61387 json | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails w... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-60009 json | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every file... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-60007 json | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-59328 json | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) wi... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-59327 json | Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attr... | Not Provided | 2026-07-30 | 2026-07-30 |