← Vulnerability feed

Vulnerability record · CVE-2026-6918 · published 5 May 2026

CVE-2026-6918: Eclipse openj9 out-of-bounds read vulnerability

Eclipse · Openj9

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

8.7 CVSS 4.0 High EPSS 1.2% · top 33.6% CWE-125 · Out-of-bounds readCWE-1286 · CWE-1286
8.7CVSS 4.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 2 tagged exploit
15 Jul 2026Last modified by NVD

Description

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-6918 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41035Eclipse openj9 execution with unnecessary privileges vulnerabilityIn Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.EPSS 1.8%9.8CVE-2020-27221Eclipse openj9 stack-based buffer overflow vulnerabilityIn Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …EPSS 1.5%9.8CVE-2019-11772Eclipse openj9 out-of-bounds write vulnerabilityIn Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that …EPSS 2.1%9.8CVE-2018-12547Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…EPSS 2.7%9.8CVE-2018-12549Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…EPSS 2.3%9.8CVE-2018-12548Eclipse openj9 memory buffer overflow vulnerabilityIn OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…EPSS 1.1%9.1CVE-2023-2597Eclipse openj9 classic buffer overflow vulnerabilityIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…EPSS 0.43%9.1CVE-2019-17631Eclipse openj9 improper authorization vulnerabilityFrom Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-6918), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.