VYPR

che-dashboard

by Eclipse

CVEs (1)

  • CVE-2026-86590MedSep 8, 2026
    risk 0.34cvss epss

    In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery…