CVE-2026-85201

Source
https://cve.org/CVERecord?id=CVE-2026-85201
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85201.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85201
Published
2026-09-07T10:01:07Z
Modified
2026-09-10T03:30:48Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L CVSS Calculator
Summary
[none]
Details

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.

Database specific
{
    "cna_assigner": "eclipse",
    "cwe_ids": [
        "CWE-1284",
        "CWE-789"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85201.json"
}
References

Affected packages

Git / github.com/eclipse-ankaios/ankaios

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-ankaios/ankaios
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.1.0"
        },
        {
            "fixed": "1.0.1"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.2.0
v0.2.0-rc1
v0.3.0
v0.3.1
v0.3.1-pre
v0.4.0
v0.4.0-rc1
v0.5.0
v0.5.0-rc1
v0.6.0
v0.6.0-rc1
v0.7.0
v0.7.0-rc1
v1.*
v1.0.0
v1.0.0-rc1
v1.0.1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85201.json"