API Gateway Vulnerability in Eclipse aeriOS with KrakenD Parameter Exposure
CVE-2026-82955
9CRITICAL
What is CVE-2026-82955?
In the development version of Eclipse aeriOS, the API Gateway component's KrakenD instance had the disable_jwk_security parameter set to true by default, disabling TLS certificate verification for retrieving the JSON Web Key Set (JWKS). This flaw can permit attackers to intercept communications, potentially compromising the validation of bearer tokens by substituting a malicious JWKS. The issue has now been rectified by allowing the parameter to be configurable via the Helm chart, defaulting to false to ensure that TLS verification is enforced in typical operations.
Affected Version(s)
Eclipse aeriOS 371ea2101e42aa6503161ce08bbe986e319a9c2f
