CVE-2026-10055: SSRF

Published Jul 3, 2026
·
Updated

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller.

Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service connection can issue server-side HTTP requests to localhost or other backend-reachable hosts and read their responses, exposing internal administrative endpoints, cloud instance metadata services, and other resources that are intentionally outside the browser network boundary.

The vulnerability affects deployments where the Theia service connection is reachable by untrusted users (for example, multi-tenant or publicly-reachable Theia deployments).

Affected Software

1 affected component
Eclipse Theia Eclipse Theia>=undefined

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict access to the Theia service connection so that only trusted users/clients can reach the standard /services messaging endpoint and invoke /services/request-service, because the backend accepts attacker-controlled URLs and performs server-side HTTP requests.

    Eclipse Theia /services/request-service RPC (server-side URL fetching) = Allow only validated/allowlisted destination URLs; reject attacker-controlled URLs from untrusted clients

Event History

Jul 3, 2026
CVE Published
via MITRE·10:30 AM
Data Sourced
via MITRE·10:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10055?

The severity of CVE-2026-10055 is high with a score of 8.5.

2

What is CVE-2026-10055?

CVE-2026-10055 is a vulnerability in Eclipse Theia that allows an attacker to send a controlled URL to a backend service, leading to potential server-side request forgery (SSRF) and information leakage.

3

How do I fix CVE-2026-10055?

To fix CVE-2026-10055, update to the latest version of Eclipse Theia where the issue has been addressed.

4

What are the potential impacts of CVE-2026-10055?

The potential impacts of CVE-2026-10055 include unauthorized access to sensitive data through server-side request forgery.

5

Which versions of Eclipse Theia are affected by CVE-2026-10055?

CVE-2026-10055 affects Eclipse Theia versions from 1.26.0 onwards.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203