CVE-2026-86671High· 8.4▾ TwilightIn Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In Eclipse Che versions 7.29.0 and later, the GET /api/scm/resolve and POST /api/factory/resolver endpoints pass an attacker-controlled URL to URLFetcher.fetch(), which calls new URL(url).openConnection() with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at file:///var/run/secrets/kubernetes.io/serviceaccount/token), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an Authorization header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose parent.uri points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86590Medium· 6.3In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering
CVE-2026-102722Medium· 6.9In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply
CVE-2026-86862Medium· 6.5pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql
CVE-2026-69805High· 7.5External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-101322High· 8.3In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin
CVE-2025-67732Medium· 6.5Dify is an open-source LLM app development platform