CVE-2026-85201

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 11:17

Updated : 2026-09-08 16:18


NVD link : CVE-2026-85201

Mitre link : CVE-2026-85201

CVE.ORG link : CVE-2026-85201


JSON object : View

Products Affected

No product.

CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-1284

Improper Validation of Specified Quantity in Input