CVE-2022-25897

MEDIUM

Eclipse Milo < 0.6.8 - Resource Allocation Without Limits

Title source: rule
STIX 2.1

Description

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

References (4)

Core 4
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/eclipse/milo/pull/1031
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/eclipse/milo/issues/1030

Scores

CVSS v3 5.9
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (2)
eclipse/milo < 0.6.8
org.eclipse.milo/sdk-server 0 - 0.6.8Maven
Published Sep 08, 2022
Tracked Since Feb 18, 2026