CVE-2026-86671
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Summary
In Eclipse Che versions 7.29.0 and later, the GET /api/scm/resolve and POST /api/factory/resolver endpoints pass an attacker-controlled URL to URLFetcher.fetch(), which calls new URL(url).openConnection() with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at file:///var/run/secrets/kubernetes.io/serviceaccount/token), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an Authorization header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose parent.uri points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Che | 7.29.0 < 7.123.0 | affected |
Weaknesses
- CWE-918: CWE-918
- CWE-73: CWE-73
- CWE-522: CWE-522
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/620
- https://redhat.atlassian.net/browse/CRW-11956
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/278
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.