VYPR

Lyo

by Eclipse

CVEs (2)

  • CVE-2026-18918CriAug 28, 2026
    risk 0.52cvss —epss 0.00

    In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An…

  • CVE-2021-41042MedJul 7, 2022
    risk 0.28cvss 5.3epss 0.01

    In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.