CVE-2026-6918: Eclipse OPENJ9

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

Affected products

  • Eclipse OPENJ9: from 0.21.0, before 0.59.0 (fixed in 0.59.0)

Published 2026-05-05. Last modified 2026-07-15.