CVE-2026-86590
Last modified
CVE-2026-86590 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal network addresses, including the cloud instance metadata service (169.254.169.254), loopback interfaces, RFC-1918 private ranges, and in-cluster Kubernetes services.
Description
In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal network addresses, including the cloud instance metadata service (169.254.169.254), loopback interfaces, RFC-1918 private ranges, and in-cluster Kubernetes services. The operator-configured allowlist (spec.devEnvironments.allowedSources.urls) is not consulted. The vulnerability is fixed in version 7.122.0, which adds private-address blocking, IPv4-mapped IPv6 bypass prevention, operator allowlist enforcement, and disables HTTP redirects on the outbound request.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | Eclipse Che | >= 7.79.0, < 7.122.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86590?
How severe is CVE-2026-86590?
How do I fix CVE-2026-86590?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8655Multiple Memory overflow vulnerabilities in NetScaler ADC an…9.8
- CVE-2026-86550NuBrowser lacks protocol whitelist validation for the S.brow…6.5
- CVE-2026-8656Versions of the package jsondiffpatch before 0.7.6 are vulne…6.1
- CVE-2026-8657Versions of the package jsondiffpatch before 0.7.6 are vulne…8.2
- CVE-2026-8658OS Command Injection vulnerability in Rapid7 InsightConnect …8.8
- CVE-2026-8659OS Command Injection vulnerability in Rapid7 InsightConnect …8.8
- CVE-2026-86597Insertion of sensitive information into log files in the Sno…6.5
- CVE-2026-8660OS Command Injection vulnerability in the ping action of Rap…9.8
- CVE-2026-8661Server-Side Request Forgery in the markdown_to_pdf action of…4.8
- CVE-2026-8662Path Traversal vulnerability in the create_archive function …4.3
- CVE-2026-8663OS Command Injection vulnerability in Rapid7 InsightConnect …8.8
- CVE-2026-8664OS Command Injection vulnerability in Rapid7 InsightConnect …8.8
Are you affected by CVE-2026-86590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
