VYPR

ankaios

by Eclipse

Source repositories

CVEs (2)

  • CVE-2026-84173HigSep 7, 2026
    risk 0.47cvss epss

    In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a…

  • CVE-2026-85201MedSep 7, 2026
    risk 0.37cvss epss

    In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length,…