Equinox Eclipse Equinox

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Eclipse Equinox.

By the Year

In 2026 there have been 2 vulnerabilities in Eclipse Equinox with an average score of 9.3 out of ten. Equinox did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 2 9.30
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 8.10

It may take a day or so for new Equinox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Eclipse Equinox Security Vulnerabilities

Eclipse Equinox OSGi RCE via Console (<=3.7.2)
CVE-2023-54344 9.3 - Critical - May 05, 2026

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections.

Missing Authentication for Critical Function

Eclipse Equinox OSGi 3.8-3.18 RCE via console fork command
CVE-2023-54342 9.3 - Critical - May 05, 2026

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.

Missing Authentication for Critical Function

In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos
CVE-2021-41033 8.1 - High - September 13, 2021

In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Eclipse Equinox or by Eclipse? Click the Watch button to subscribe.

Eclipse
Vendor

subscribe