CVE-2026-10055
Eclipse Foundation Eclipse Theia
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service connection can issue server-side HTTP requests to localhost or other backend-reachable hosts and read their responses, exposing internal administrative endpoints, cloud instance metadata services, and ot...
- CVSS
- 8.5
- EPSS
- 0.30% 21.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.03