What is CVE-2026-63252?
CVE-2026-63252 is a vulnerability in Eclipse Milo versions 0.6.0 through 1.1.4 where UASC server transport handlers fail to release partial message chunks upon channel disconnect, leading to direct memory exhaustion via repeated incomplete chunk transmissions. Affected users should upgrade the library to mitigate the risk of remote denial-of-service attacks.
Azərbaycanca: CVE-2026-63252 Eclipse Milo kitabxanasında UASC server nəqliyyat işləyicilərində təsdiqlənməmiş uzaqdan istifadəçiyə qismən mesaj hissələrini təkrar göndərməklə birbaşa yaddaşı tükəndirməyə imkan verən qüsurdur. 0.6.0-dan 1.1.4-ə qədər versiyalar təsirlənir; kanal bağlantısı kəsilərkən hissələr düzgün buraxılmadığı üçün yaddaş sızması baş verir. Bu boşluqdan qorunmaq üçün kitabxananı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Eclipse Milo
FAQ2
Which Eclipse Milo versions are affected by CVE-2026-63252?
Eclipse Milo versions 0.6.0 through 1.1.4 are affected by this vulnerability.
What is the recommended mitigation for CVE-2026-63252?
Users should upgrade the Eclipse Milo library to mitigate the risk of remote denial-of-service attacks caused by the memory leak.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.