MEDIUM 6.8 NVD
CVE-2026-85201
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received thro
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
References
- https://github.com/eclipse-ankaios/ankaios/pull/791
- https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.2
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/900
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-09-07 via NVD.
vulnfeed aggregates 2664 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.