CVE-2026-84175

Source
https://cve.org/CVERecord?id=CVE-2026-84175
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84175.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84175
Aliases
  • GHSA-7f3j-xpvm-wwmg
Published
2026-09-02T09:45:58.359Z
Modified
2026-09-04T03:47:31.238684083Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the redirect target and without a hop limit. An authenticated user who is permitted to create a Thing, or who holds WRITE permission on an existing Thing, can thereby cause the Things service to issue arbitrary HTTP GET requests from inside the deployment's network — including to cloud instance-metadata endpoints and other internal services — and can use the differing error responses returned to the caller to enumerate internal services. Versions 2.4.0 to 2.5.x contain the same code, but are only affected where the operator explicitly enabled the WoT integration feature toggle, which is disabled by default in those versions.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84175.json",
    "cna_assigner": "eclipse",
    "cwe_ids": [
        "CWE-674",
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/eclipse-ditto/ditto

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-ditto/ditto
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.9.0"
        },
        {
            "last_affected": "3.9.6"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "last_affected": "3.8.12"
        },
        {
            "introduced": "2.4.0"
        },
        {
            "fixed": "3.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.4.0
3.*
3.0.0
3.1.0
3.1.0-M1
3.2.0
3.3.2
3.3.2-M1
3.3.3
3.3.4
3.4.0
3.4.0-M1
3.4.0-M2
3.5.0
3.6.0
3.7.0
3.8.0
3.8.0-M1
3.8.0-M2
3.8.0-M3
3.8.0-M4
3.8.0-M5
3.8.0-M6
3.8.1
3.8.10
3.8.11
3.8.12
3.8.2
3.8.3
3.8.4
3.8.5
3.8.6
3.8.7
3.8.8
3.8.9
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.9.6
helm-chart-4.*
helm-chart-4.0.0
helm-chart-4.1.0
helm-chart-4.2.0
helm-chart-4.3.0
helm-chart-4.4.0
helm-chart-4.5.0
helm-chart-4.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84175.json"