CVE-2026-103416: CWE-787 Out-of-bounds write in Eclipse Foundation Eclipse ThreadX - NetX Duo
Description
CVE-2026-103416 is a critical out-of-bounds write vulnerability in Eclipse ThreadX NetX Duo 6.5.1.202602 and earlier versions. It occurs during the TLS 1.3 handshake message caching process, where a handshake message larger than the cache can overwrite adjacent memory in the session control block. This flaw can be triggered by a malicious or compromised server before certificate authentication, without requiring a valid server certificate.
CVSS v4.0
Score 9.3critical
Affected software
Eclipse Foundation
Eclipse ThreadX - NetX Duo
pkg:github/eclipse-threadx/netxduoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-787) involves an out-of-bounds write in the TLS 1.3 handshake message cache within Eclipse ThreadX NetX Duo versions up to 6.5.1.202602. When a handshake message exceeds the allocated cache size, it overwrites memory beyond the cache into the session control block, which contains pointers. An attacker controlling or impersonating a server can exploit this by sending an oversized handshake message before certificate authentication completes, bypassing the need for a valid server certificate.
Potential Impact
Successful exploitation can lead to memory corruption in the client, potentially allowing arbitrary code execution or denial of service. Because the attack can be initiated before server certificate authentication, it lowers the barrier for exploitation by malicious or compromised servers. The CVSS 4.0 base score is 9.3, indicating critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid connecting to untrusted or potentially malicious TLS 1.3 servers. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-09-30T14:46:53.599Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac60e7e2cdf04f656324a73
Added to database: 10/07/2026, 09:18:54 UTC
Last enriched: 10/07/2026, 09:33:28 UTC
Last updated: 10/07/2026, 09:33:28 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.