CVE-2026-6918
Published May 5, 2026
·Updated
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
Affected Software
2 affected components
Eclipse Openj9>=0.21<=0.58
Eclipse Openj9>=0.21.0<0.59.0
Remediation
Patch Available
Event History
May 5, 2026
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6918?
CVE-2026-6918 is considered to be a high severity vulnerability due to its potential to cause service disruptions.
2
How do I fix CVE-2026-6918?
To fix CVE-2026-6918, upgrade Eclipse OpenJ9 to a version later than 0.58.
3
Who is affected by CVE-2026-6918?
CVE-2026-6918 affects all versions of Eclipse OpenJ9 from 0.21 to 0.58.
4
What type of attack is associated with CVE-2026-6918?
CVE-2026-6918 is associated with a pre-authentication remote denial-of-service attack.
5
Can CVE-2026-6918 be exploited remotely?
Yes, CVE-2026-6918 can be exploited remotely by sending a specially crafted TCP message.