Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[lyo-dev] [ANN] Lyo 6.0.1.Final and 7.0.0.Beta3 released addressing a CVE

Dear Lyo users,

Today we are releasing an important security update (6.0.1.Final and 7.0.0.Beta3) for issues affecting Lyo servers featuring OAuth 1.0 support. The issue affects Lyo servers with 2-legged OAuth support where your filter is based on AbstractAdapterCredentialsFilter. If you only support 3-legged OAuth or use CredentialsFilter generated by Lyo Designer, you should not be affected. We recommend that you upgrade to a patched version regardless.

CVE number assigned to this issue is CVE-2026-18918 and will be published shortly. The CVSS score is

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Red (9.1 CRITICAL)

Best regards,
Andrew
Eclipse Lyo project lead

Back to the top