Exhaustion Vulnerability in Eclipse Milo Affecting Quota Management
CVE-2026-61387
What is CVE-2026-61387?
Eclipse Milo versions 1.0.0 through 1.1.4 exhibit a vulnerability in their monitored-item quota accounting mechanism. An unchecked error during the creation of monitored items can lead to the exhaustion of global quota resources. Specifically, deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can cause a StackOverflowError during the decoding process. This allows an unauthenticated remote client to deplete the finite quota of monitored items, hindering further item creation for all clients until the server is restarted. While existing monitored items continue to function normally, the inability to create new monitored items poses significant operational challenges.
Affected Version(s)
Eclipse Milo 1.0.0 < 1.1.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
