GHSA-jrjq-9cmf-3h6fCriticalCVSS 7.4

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable...

Published
August 4, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

🔗 References (5)