CVE-2026-6918
published 2026-05-05CVE-2026-6918: In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.52%
40.5th percentile
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | >= 0.21.0 < 0.59.0 | 0.59.0 |
| eclipse_foundation | eclipse_openj9 | >= 0.21 < 0.59 | 0.59 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Eclipse Open9J: Eclipse Open9J: Denial of Service in JITServer via crafted TCP message
vendor_redhat·2026-05-05·CVSS 8.7
CVE-2026-6918 [HIGH] CWE-1286 Eclipse Open9J: Eclipse Open9J: Denial of Service in JITServer via crafted TCP message
Eclipse Open9J: Eclipse Open9J: Denial of Service in JITServer via crafted TCP message
A flaw was found in Eclipse Open9J and JITServer. A remote attacker, without needing to authenticate, can send a specially crafted 32-byte TCP message to JITServer. This action can cause JITServer to crash, leading to a Denial of Service (DoS) for affected systems.
Package: java-21-ibm-semeru-certified-jdk (Red Hat Enterprise Linux 10) - Affected
VulDB
Eclipse OpenJ9 up to 0.58 JITServer out-of-bounds (GHSA-q393-vr4c-969r)
vuldb·2026-05-05·CVSS 8.7
CVE-2026-6918 [HIGH] Eclipse OpenJ9 up to 0.58 JITServer out-of-bounds (GHSA-q393-vr4c-969r)
A vulnerability was found in Eclipse OpenJ9 up to 0.58. It has been classified as problematic. This impacts an unknown function of the component JITServer. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-6918. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
https://github.com/eclipse-openj9/openj9/pull/23793https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969rhttps://access.redhat.com/errata/RHSA-2026:22328https://access.redhat.com/security/cve/CVE-2026-6918https://bugzilla.redhat.com/show_bug.cgi?id=2466741https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-q393-vr4c-969rhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6918.json
2026-05-05
Published