CVE-2026-102728: Eclipse Foundation Netx Duo
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.
Affected products
- Eclipse Foundation Netx Duo: up to and including 6.5.1.202602
Published 2026-09-29. Last modified 2026-09-30.