{"id":"CVE-2026-63252","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63252","summary":null,"details":"In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server.","published":"2026-08-04T12:03:18.647Z","modified":"2026-08-12T16:09:55.970284Z","cvss":null,"epss":{"score":0.00413,"percentile":0.34426,"asOf":"2026-08-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/eclipse-milo/milo/commit/459715793ec54b0f33367a14f94264500a0d872b","label":"eclipse-milo/milo@4597157"},"references":[{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/179"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63252.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63252"},{"type":"FIX","url":"https://github.com/eclipse-milo/milo/commit/459715793ec54b0f33367a14f94264500a0d872b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:09:55.970284Z"}}