HTTP Redirection Vulnerability in Eclipse Ditto Web of Things Service
CVE-2026-84175
5.3MEDIUM
What is CVE-2026-84175?
In affected versions of Eclipse Ditto, the Things service inadequately handles HTTP requests made to retrieve Web of Things ThingModels. It fetches these models from user-defined URLs without validating the host and does not enforce a limit on the number of redirects. This oversight allows authenticated users with permissions to create or modify Things to orchestrate arbitrary HTTP GET requests from within the network. This could lead to exposure of sensitive internal services and endpoints by exploiting the varying error messages returned during these unauthorized requests.
Affected Version(s)
Eclipse Ditto 3.9.0 <= 3.9.6
Eclipse Ditto 3.0.0 <= 3.8.12
Eclipse Ditto 2.4.0 < 3.0.0
