Known Vulnerabilities for Eclipse Che by Eclipse Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Eclipse Che" by "Eclipse Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86590 json | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a c... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-85201 json | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delim... | Not Provided | 2026-09-07 | 2026-09-07 |
| CVE-2026-85199 json | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-control... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84736 json | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator com... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84175 json | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supp... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-84173 json | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-se... | Not Provided | 2026-09-07 | 2026-09-07 |
| CVE-2026-82958 json | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateT... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82955 json | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance include... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82217 json | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, sug... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-82180 json | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, Ce... | Not Provided | 2026-09-03 | 2026-09-03 |