CVE-2026-63252
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
04/08/2026
Last modified:
05/08/2026
Description
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:* | 0.6.0 (including) | 1.1.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



