CVE-2026-63252

Summary

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationEclipse Milo0.6.0 <= 1.1.4affected

Weaknesses

  • CWE-401: CWE-401

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References