CVE-2026-102761: Eclipse Foundation Netx Duo
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block. The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.
Affected products
- Eclipse Foundation Netx Duo: from 6.2.0, up to and including 6.5.1.202602
Published 2026-09-29. Last modified 2026-09-30.