API Gateway Vulnerability in Eclipse aeriOS with KrakenD Parameter Exposure
CVE-2026-82955

9CRITICAL

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-82955?

In the development version of Eclipse aeriOS, the API Gateway component's KrakenD instance had the disable_jwk_security parameter set to true by default, disabling TLS certificate verification for retrieving the JSON Web Key Set (JWKS). This flaw can permit attackers to intercept communications, potentially compromising the validation of bearer tokens by substituting a malicious JWKS. The issue has now been rectified by allowing the parameter to be configurable via the Helm chart, defaulting to false to ensure that TLS verification is enforced in typical operations.

Affected Version(s)

Eclipse aeriOS 371ea2101e42aa6503161ce08bbe986e319a9c2f

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.