CVE-2026-85201
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
- EPSS probability
- 0.11%
- CWE
- CWE-789, CWE-1284
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- Eclipse Foundation Eclipse Ankaios
Weakness type
Related vulnerabilities
- CVE-2026-89092 — Stack overflow in nscd due to unbounded alloca use
- CVE-2026-88045 — rclone: S3 multipart declared-length memory exhaustion
- CVE-2026-83530 — Uncontrolled Memory Allocation in cel-go
- CVE-2026-86776 — KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size
- CVE-2026-19204 — A client may send a WebSocket frame with an unknown opcode and a very large declared payload...
- CVE-2026-85445 — MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count
- CVE-2026-85442 — MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation
- CVE-2026-84888 — RightNow-AI OpenFang tool_runner.rs shell_exec memory allocation