CVE Explorer
CVE-2026-9561
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemot
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-348","description":"CWE-348: Use of Less Trusted Source","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Eclipse Kura","repo":"https://github.com/eclipse-kura/kura","vendor":"Eclipse Foundation","versions":[{"lessThanOrEqual":"5.6.1","status":"affected","version":"5.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"N…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
3 source assertions{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-807","description":"CWE-807: Reliance on Untrusted Inputs in a Security Decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-348","description":"CWE-348: Use of Less Trusted Source","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/117"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2edbb646ce1f393a4de55ee1a05084aade3f15cf72a48df3cb691a66fd4d4a51 · sha256:61eb6d068858b06a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.