CVE-2026-85201CWE-1284CWE-789

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received…

Medium · published September 7, 2026

CVSS v4.0
6.8
EPSS
In the wild
Unconfirmed
What it is

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.

The record
Technical detail
CVSS v4.0
6.8 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
EPSS
Not scored
Weaknesses
CWE-1284 · Improper Validation of Specified Quantity in Input; CWE-789 · Memory Allocation with Excessive Size Value
Published
2026-09-07T10:01Z
Timeline
  • 07 SEP 10:01Z
    In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received…
    cvelistv5