8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
AI Analysis
Pre-authentication remote denial-of-service vulnerability in Eclipse OpenJ9 via crafted TCP message
Basic Information
ID
CVE-2026-6918
Source
eclipse
Published
May 5, 2026 at 12:29
Affected Product
Vendor
Eclipse Foundation
Product
Eclipse OpenJ9
Version
0.21
Affected Versions
Eclipse Foundation Eclipse OpenJ9 0.21
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Eclipse Foundation
Product
Eclipse OpenJ9
Version
0.21-0.58