PT-2026-84660 · Eclipse Foundation · Eclipse Ditto

CVE-2026-84175

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse Ditto versions 3.0.0 through 3.9.6 Eclipse Ditto versions 2.4.0 through 2.5.x
Description The Things service fetches Web of Things (WoT) ThingModels over HTTP from URLs provided by users in the definition field of a Thing or Feature. The service fails to validate the target host and follows HTTP redirects without re-validating the target or implementing a hop limit. An authenticated user with permissions to create a Thing or with WRITE access to an existing Thing can force the service to send arbitrary HTTP GET requests from within the deployment network. This allows for the targeting of cloud instance-metadata endpoints and other internal services, enabling the enumeration of internal services based on the error responses received.
Recommendations Update to a version newer than 3.9.6. For versions 2.4.0 through 2.5.x, disable the WoT integration feature toggle. Restrict WRITE permissions for creating or modifying Things to trusted users only.

Exploit

Fix

Uncontrolled Recursion

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84175
GHSA-7F3J-XPVM-WWMG

Affected Products

Eclipse Ditto