PT-2026-84660 · Eclipse Foundation · Eclipse Ditto
CVE-2026-84175
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Ditto versions 3.0.0 through 3.9.6
Eclipse Ditto versions 2.4.0 through 2.5.x
Description
The Things service fetches Web of Things (WoT) ThingModels over HTTP from URLs provided by users in the definition field of a Thing or Feature. The service fails to validate the target host and follows HTTP redirects without re-validating the target or implementing a hop limit. An authenticated user with permissions to create a Thing or with WRITE access to an existing Thing can force the service to send arbitrary HTTP GET requests from within the deployment network. This allows for the targeting of cloud instance-metadata endpoints and other internal services, enabling the enumeration of internal services based on the error responses received.
Recommendations
Update to a version newer than 3.9.6.
For versions 2.4.0 through 2.5.x, disable the WoT integration feature toggle.
Restrict WRITE permissions for creating or modifying Things to trusted users only.
Exploit
Fix
Uncontrolled Recursion
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Ditto