Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82955

Quick assessment

Affected
Eclipse Foundation Eclipse aeriOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Eclipse aeriOS 的当前开发版本(尚未正式发布)中,API 网关组件中包含的 KrakenD 实例将 参数硬编码为 ,且无法通过 Helm Chart 配置进行覆盖。该设置会在 KrakenD 获取用于验证 Bearer 令牌的 JSON Web Key Set(JWKS)时禁用 TLS 证书验证,从而可能允许能够拦截此通信的攻击者提供一个恶意的 JWKS,进而破坏令牌验证过程。 该问题已通过将该参数改为可通过 Helm 布尔值 进行配置来修复,并默认将其设置为 ,从而确保 TLS 证书验证默认启用

CVSS 9.0 · Critical EPSS 0.14% · P4

Affected Version Matrix 1

VendorProduct Version RangeStatus
Eclipse Foundation Eclipse aeriOS 371ea2101e42aa6503161ce08bbe986e319a9c2f< e680c69c34b82db4944517198330cc447a1e8f98 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82955

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS certificate verification when KrakenD retrieves the JSON Web Key Set (JWKS) used to validate bearer tokens, potentially allowing an attacker with the ability to intercept this communication to provide a malicious JWKS and compromise token validation. The issue has been addressed by making the parameter configurable through the boolean Helm value krakend.config.disableJwkSecurity and setting its default value to false, ensuring that TLS certificate verification is enabled by default.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Eclipse Foundation Eclipse aeriOS 371ea2101e42aa6503161ce08bbe986e319a9c2f ~ e680c69c34b82db4944517198330cc447a1e8f98 -

II. Public POCs for CVE-2026-82955

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82955

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82955 (1)

Same Patch Batch · Eclipse Foundation · 2026-09-02 · 3 CVEs total

CVE-2026-82958 7.6 HIGH CVE-2026-82958
CVE-2026-84175 5.3 MEDIUM Eclipse Ditto 3.0.0至3.9.6 服务器端请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-82955

No comments yet


Leave a comment