CVE-2026-63252 Details
Description
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.
A denial-of-service vulnerability has been identified in Eclipse Milo versions 0.6.0 through 1.1.4. The issue arises in the UASC server transport handlers, which fail to properly release retained partial message chunks when a channel disconnects. This oversight allows a remote, unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially leading to server termination.
The vulnerability has been addressed in Eclipse Milo version 1.1.6. Users should update to this version to mitigate the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eclipse-milo/milo/commit/459715793ec54b0f33367a14f94264500a0d872b | [email protected] | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/179 | [email protected] | Issue TrackingPatchVendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse milo | >= 0.6.0, < 1.1.5 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |