CVE-2026-61387
In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new monitored items until restart. Existing monitored items and other server functions remain unaffected.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.34%
- CWE
- CWE-460, CWE-772, CWE-400
- Published
- 2026-08-04
- Last modified
- 2026-08-04
Affected products
- Eclipse Foundation Eclipse Milo
Weakness type
Related vulnerabilities
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is...
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes
- CVE-2025-30157 — Envoy crashes when HTTP ext_proc processes local replies