Exhaustion Vulnerability in Eclipse Milo Affecting Quota Management
CVE-2026-61387

6.9MEDIUM

Key Information:

Vendor
CVE Published:
4 August 2026

What is CVE-2026-61387?

Eclipse Milo versions 1.0.0 through 1.1.4 exhibit a vulnerability in their monitored-item quota accounting mechanism. An unchecked error during the creation of monitored items can lead to the exhaustion of global quota resources. Specifically, deeply nested PubSub ExtensionObjects in a CreateMonitoredItems event filter can cause a StackOverflowError during the decoding process. This allows an unauthenticated remote client to deplete the finite quota of monitored items, hindering further item creation for all clients until the server is restarted. While existing monitored items continue to function normally, the inability to create new monitored items poses significant operational challenges.

Affected Version(s)

Eclipse Milo 1.0.0 < 1.1.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhinav Agarwal (GitHub: @abhinavagarwal07)
.