Cve

Eclipse Foundation GitLab incident postmortem: CVE-2026-85706

Eclipse Foundation GitLab incident postmortem: CVE-2026-85706

Mikaël Barbero

Between 12 and 14 September 2026, our GitLab instance was affected by CVE-2026-85706, a critical vulnerability in GitLab that allowed unauthenticated attackers to read files from the server. Some of those files contained sensitive credentials, and they were copied by attackers before we closed the hole. The vulnerability is now fully remediated, the exposure is contained, and our investigation is complete.

We owe the community a clear account of what happened, what we’ve done about it, and what (if anything) you need to do. This is that account.

Open VSX security update, October 2025

Open VSX security update, October 2025

Mikaël Barbero

Over the past few weeks, the Open VSX team and the Eclipse Foundation have been responding to reports of leaked tokens and related malicious activity involving certain extensions hosted on the Open VSX Registry. We want to share a clear summary of what happened, what actions we’ve taken, and what improvements we’re implementing to strengthen the security of the ecosystem.

Vulnerability in Eclipse Open VSX Registry extension publication process

Vulnerability in Eclipse Open VSX Registry extension publication process

Mikaël Barbero

On May 4th, the Eclipse Foundation (EF) Security Team received a notification from researchers at Koi Security regarding a potential issue in the Eclipse Open VSX marketplace extension publication process. The EF Security Team immediately contacted the Eclipse Open VSX team, and upon confirming the issue, work on a fix was promptly initiated.