HTTP Redirection Vulnerability in Eclipse Ditto Web of Things Service
CVE-2026-84175

5.3MEDIUM

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84175?

In affected versions of Eclipse Ditto, the Things service inadequately handles HTTP requests made to retrieve Web of Things ThingModels. It fetches these models from user-defined URLs without validating the host and does not enforce a limit on the number of redirects. This oversight allows authenticated users with permissions to create or modify Things to orchestrate arbitrary HTTP GET requests from within the network. This could lead to exposure of sensitive internal services and endpoints by exploiting the varying error messages returned during these unauthorized requests.

Affected Version(s)

Eclipse Ditto 3.9.0 <= 3.9.6

Eclipse Ditto 3.0.0 <= 3.8.12

Eclipse Ditto 2.4.0 < 3.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.