In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new monitored items until restart. Existing monitored items and other server functions remain unaffected.
References
Configurations
History
05 Aug 2026, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/eclipse-milo/milo/commit/587e35669f519b2d7f6d850a5f86ee5a76c3a2c5 - Patch | |
| References | () https://github.com/eclipse-milo/milo/commit/5f3f6da2a5ea80682e1da7c58f7a1870b09d2b43 - Patch | |
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/work_items/182 - Broken Link | |
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 - Issue Tracking, Vendor Advisory | |
| CPE | cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:* | |
| First Time |
Eclipse milo
Eclipse |
04 Aug 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-04 13:18
Updated : 2026-08-05 20:19
NVD link : CVE-2026-61387
Mitre link : CVE-2026-61387
CVE.ORG link : CVE-2026-61387
JSON object : View
Products Affected
eclipse
- milo
