Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9561

AI Predicted 5.3 Difficulty: Easy EPSS 0.20% · P11

Affected Version Matrix 1

VendorProductVersion RangeStatus
Eclipse FoundationEclipse Kura5.0.0≤ 5.6.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9561

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不可信的源
Source: CVE Program / CVE List V5
Vulnerability Title
Eclipse kura 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Eclipse kura是美国Eclipse基金会开源的一套物联网应用框架。 Eclipse kura 5.6.2之前版本存在安全漏洞,该漏洞源于信任客户端提供的X-Forwarded-For HTTP标头,可能导致未经身份验证的远程攻击者绕过基于IP的暴力破解保护,或者通过注入受害者IP地址导致对第三方拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Eclipse FoundationEclipse Kura 5.0.0 ~ 5.6.1 -

II. Public POCs for CVE-2026-9561

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9561

登录查看更多情报信息。

Other References for CVE-2026-9561 (1)

Same Patch Batch · Eclipse Foundation · 2026-07-14 · 10 CVEs total

CVE-2026-578989.0 CRITICALEclipse BaSyx Java Server SDK 路径遍历漏洞
CVE-2024-77087.5 HIGHEclipse Jetty 资源管理错误漏洞
CVE-2026-67905.3 MEDIUMEclipse Jetty 输入验证错误漏洞
CVE-2026-83845.3 MEDIUMEclipse jetty 授权问题漏洞
CVE-2026-136994.3 MEDIUMDatabroker 0.6.1 PublishValue missing data_point panic
CVE-2026-15076Eclipse Vert.x 输入验证错误漏洞
CVE-2026-15075Eclipse vert.x 信息泄露漏洞
CVE-2026-10051Eclipse Jetty 信息泄露漏洞
CVE-2026-12606Eclipse Glassfish 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-9561

No comments yet


Leave a comment