๐Ÿ” CVE Alert

CVE-2026-86671

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.

CWE CWE-918 CWE-73 CWE-522
Vendor eclipse foundation
Product eclipse che
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse che

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse che are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Che
7.29.0 < 7.123.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/620 redhat.atlassian.net: https://redhat.atlassian.net/browse/CRW-11956 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/278

Credits

Eclipse Foundation Security Team