CVE-2026-6918

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:* 0.21.0 (including) 0.59.0 (excluding)