Eclipse lyo
This hub aggregates every CVE we track for Eclipse lyo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
2
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-102026-09
Latest CVEs
The 2 most recently published vulnerabilities affecting Eclipse lyo.
- CVE-2026-18918OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default
- CVE-2021-41042In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an externa...5.3
Product normalization is registry-driven with AI assist and human review. How it works