Eclipse Foundation Vulnerabilities and Affected Products
Vulnerabilities associated with Eclipse Glassfish.
Products
Clear product- Eclipse Glassfish12 vulnerabilities
- ThreadX12 vulnerabilities
- NetX Duo11 vulnerabilities
- Eclipse Theia10 vulnerabilities
- Eclipse Jetty9 vulnerabilities
- Eclipse Milo6 vulnerabilities
- Jetty6 vulnerabilities
- Eclipse OMR4 vulnerabilities
- Eclipse Vert.x4 vulnerabilities
- Mosquitto4 vulnerabilities
- OpenJ94 vulnerabilities
- USBX4 vulnerabilities
- Eclipse CSI - PIA3 vulnerabilities
- Eclipse BaSyx2 vulnerabilities
- Eclipse KUKSA - Databroker2 vulnerabilities
- Eclipse Open VSX2 vulnerabilities
- Eclipse OpenJ92 vulnerabilities
- Eclipse OpenMQ2 vulnerabilities
- Eclipse ThreadX - NetX Duo2 vulnerabilities
- Glassfish2 vulnerabilities
- NextX Duo2 vulnerabilities
- Open J92 vulnerabilities
- Parsson2 vulnerabilities
- Vert.x2 vulnerabilities
- BlueChi1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12605CRITICAL | Generated title:Eclipse GlassFish DownloadServlet CSRF and SSRF Leading to Admin Token Leakage and Domain TakeoverIn Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires. CWE-918Aug 6, 2026 | CVSS9.6v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12606MEDIUM | Generated title:Eclipse Grizzly HTTP Request Smuggling via Malformed Trailer HeaderEclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the behavior that fixes the vulnerability - set org.glassfish.grizzly.http.STRICT_HEADER_NAME_VALIDATION_RFC_9110 and org.glassfish.grizzly.http.STRICT_HEADER_VALUE_VALIDATION_RFC_9110 system properties to "true". CWE-444Jul 14, 2026 | CVSS6.3v4.0 | EPSS0.188% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2586CRITICAL | GlassFish's Administration Console is Vulnerable to RCEAn authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown. | CVSS9.1v3.1 | EPSS0.842% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2587CRITICAL | GlassFish's gadget handler is vulnerable to RCEA critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise… CWE-917May 19, 2026 | CVSS9.6v3.1 | EPSS0.646% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24457CRITICAL | Generated title:Eclipse OpenMQ Unsafe Configuration Parsing Path Traversal VulnerabilityAn unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2. | CVSS9.1v3.1 | EPSS0.616% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9408HIGH | Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpointsIn Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. CWE-918Jul 16, 2025 | CVSS8.9v4.0 | EPSS0.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10032MEDIUM | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration ConsoleIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. CWE-79Jul 16, 2025 | CVSS6.1v4.0 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10031MEDIUM | Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modificationsIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system. CWE-79Jul 16, 2025 | CVSS5.8v4.0 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10029MEDIUM | Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration ConsoleIn Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console. CWE-79Jul 16, 2025 | CVSS4.5v4.0 | EPSS0.198% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9343MEDIUM | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration ConsoleIn Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. CWE-79Jul 16, 2025 | CVSS6.1v4.0 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9342MEDIUM | Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attemptsIn Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection . CWE-307Jul 16, 2025 | CVSS6.3v4.0 | EPSS0.407% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Eclipse Glassfish: URL redirection vulnerability to untrusted sitesIn Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/'). CWE-601Sep 11, 2024 | CVSS-v4.0 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |