{
  "id": "CVE-2026-86671",
  "url": "https://spydr.io/cve/CVE-2026-86671",
  "published": "2026-10-05T17:17:16.910Z",
  "modified": "2026-10-05T20:17:27.720Z",
  "score": 8.4,
  "severity": "high",
  "cvss_version": "4.0",
  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
  "score_source": "eclipse.org",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "Eclipse Foundation"
  ],
  "products": [
    "Eclipse Foundation Eclipse Che"
  ],
  "cwes": [
    "CWE-73",
    "CWE-522",
    "CWE-918"
  ],
  "description": "In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.",
  "status": "Received",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": 8.4,
    "cvss_v31": null,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/278",
      "tags": []
    },
    {
      "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/620",
      "tags": []
    },
    {
      "url": "https://redhat.atlassian.net/browse/CRW-11956",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86671",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
