High severity7.4NVD Advisory· Published Aug 4, 2026· Updated Aug 5, 2026
CVE-2026-60007
CVE-2026-60007
Description
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fbnvdPatch
- gitlab.eclipse.org/security/cve-assignment/-/work_items/183nvdIssue TrackingPatchVendor Advisory
- gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.