No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Request Forgery in Eclipse Che Dashboard Resolver Endpoint Exposes Internal Network Data | |
| First Time appeared |
Eclipse
Eclipse che |
|
| Vendors & Products |
Eclipse
Eclipse che |
Tue, 08 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal network addresses, including the cloud instance metadata service (169.254.169.254), loopback interfaces, RFC-1918 private ranges, and in-cluster Kubernetes services. The operator-configured allowlist (spec.devEnvironments.allowedSources.urls) is not consulted. The vulnerability is fixed in version 7.122.0, which adds private-address blocking, IPv4-mapped IPv6 bypass prevention, operator allowlist enforcement, and disables HTTP redirects on the outbound request. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-09-08T12:22:14.772Z
Reserved: 2026-09-08T07:20:53.477Z
Link: CVE-2026-86590
Updated: 2026-09-08T12:22:08.372Z
Status : Deferred
Published: 2026-09-08T10:17:14.197
Modified: 2026-09-08T14:15:01.243
Link: CVE-2026-86590
No data.
OpenCVE Enrichment
Updated: 2026-09-08T10:30:05Z