Impact
In Eclipse Milo versions 0.6.0 through 1.1.4, the UASC server transport handlers do not release retained partial message chunks when a channel disconnects. This flaw allows a remote, unauthenticated client to replay incomplete data fragments and disconnect repeatedly, draining the pool of direct memory and ultimately causing the server to terminate. The weakness is a memory leak (CWE-401).
Affected Systems
The vulnerability affects the Eclipse Foundation Eclipse Milo product. All releases from version 0.6.0 up to and including 1.1.4 are impacted. No later major releases are listed as affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the exploitability is amplified by the fact that any unauthenticated remote client can trigger the attack by sending partial chunks over a network connection. With no EPSS score available and the vulnerability not yet listed in CISA KEV, the concrete risk depends on deployment exposure. However, the high CVSS combined with the simple network‑based attack vector means that an attacker can perform a denial‑of‑service attack without needing privileged access or authentication.
OpenCVE Enrichment