CVE-2019-10249: Eclipse Xtend
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
Affected products
Published 2019-05-06. Last modified 2026-06-17.