Memory Allocation Vulnerability in Eclipse Ankaios by Eclipse
CVE-2026-85201

6.8MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-85201?

In Eclipse Ankaios versions 0.1.0 through 1.0.1, there exists an issue where the agent fails to limit the length of declared workloads in the length-delimited protobuf messages sent through the Control Interface FIFO. This vulnerability allows a workload with Control Interface access to specify an excessively long message length, leading to unbounded memory allocation. Such a scenario can result in the premature termination of the Ankaios agent process, disrupting orchestration services for all workloads it manages.

Affected Version(s)

Eclipse Ankaios 0.1.0 <= 1.0.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.