在 Eclipse Ditto 的 Node.js JavaScript 客户端中, 包的所有已发布版本(从 2.0.0 到 3.9.0)及其前身包 (从 1.0.0 到 2.1.0)存在一个安全漏洞: 在这些版本中,WebSocket 传输层在创建底层 WebSocket 连接时,硬编码设置了 。因此,对于所有 (加密的 WebSocket Secure)连接,证书链验证和主机名验证均被禁用。并且,没有任何构建器选项、构造器参数或环境变量允许应用程序重新启用这些验证。 这意味着,若攻击者处于能够拦截该连接的位置(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Ditto | 2.0.0 ~ 3.8.1 | - |
|
| Eclipse Foundation | Eclipse Ditto | 1.0.0 ~ 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86464 | 9.9 CRITICAL | CVE-2026-86464 |
| CVE-2026-12611 | 8.7 HIGH | Jetty HTTP/2竞态条件导致服务器无响应 |
| CVE-2026-19203 | 8.3 HIGH | Jetty特制HTTP分块请求致请求走私漏洞 |
| CVE-2026-86590 | 6.3 MEDIUM | Eclipse Che 7.79.0-7.121.0 服务端请求伪造(SSRF) |
No comments yet