← Back to search

CVE-2026-63252

7.5 HIGHpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows remote unauthenticated clients to exhaust server memory by sending incomplete message chunks and disconnecting repeatedly, potentially crashing the server.
Exploitability
Exploitation is relatively easy as it requires only sending incomplete messages and disconnecting; no authentication is needed.
Blast radius
If exploited, this could lead to a denial of service for affected servers, impacting availability and reliability.
Prioritized remediation
Update to Eclipse Milo versions later than 1.1.4 or apply vendor-provided patches immediately.
dosmemory-exhaustionunauth

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-401

Vendors

eclipse

Products

milo

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.