CVE-2026-10055Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service connection can issue server-side HTTP requests to localhost or other backend-reachable hosts and read their responses, exposing internal administrative endpoints, cloud instance metadata services, and other resources that are intentionally outside the browser network boundary. The vulnerability affects deployments where the Theia service connection is reachable by untrusted users (for example, multi-tenant or publicly-reachable Theia deployments).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 107-0607-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH severity CVE-2026-10055 (CVSS 8.5) affects Eclipse Theia v1.26.0+ Server-Side Request Forgery allows attackers to access internal endpoints & cloud metadata. Impact: Multi-tenant/public deployments at risk. #CVE #Vulnerability #PatchNow https://t.co/Y5ro93Tx7C

    Post summary

    The tweet discloses a high‑severity Server‑Side Request Forgery flaw (CVE‑2026‑10055) in Eclipse Theia v1.26.0+, warning that attackers can reach internal services and cloud metadata in multi‑tenant setups.

    0000059
    66 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-10055 Eclipse Theia SSRF could let attackers make backend requests to internal services, exposing cloud IDE environments to internal-resource access risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-03/TIER_2_CVE-2026-10055.md #CyberSecurity #CloudSecurity #VulnerabilityManagement

    Post summary

    CVE-2026-10055 is an SSRF vulnerability in Eclipse Theia that could allow attackers to access internal services within cloud IDE environments. No evidence of exploit, patch, or active exploitation is provided.

    0000051
    56 followersView on X

Explore more