Description
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.
Published: 2026-09-08
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Data Disclosure and Manipulation via disabled TLS validation
Action: Immediate Patch
AI Analysis

Impact

The Eclipse Ditto Node.js JavaScript client hard‑codes the WebSocket option rejectUnauthorized to false, disabling certificate and hostname verification for all wss:// connections. This flaw permits an attacker who can intercept the traffic to perform a man‑in‑the‑middle attack, complete the TLS handshake with any certificate, and then read or inject Authorization headers and Ditto Protocol messages. The weakness is a combination of insecure default configuration (CWE‑295), lack of proper authentication (CWE‑297) and weak certificate handling (CWE‑300). The result can be full disclosure of credentials, tampering with device data, and arbitrary command injection into the Ditto protocol.

Affected Systems

Eclipse Foundation’s Eclipse Ditto product, specifically the Node.js JavaScript client packages @eclipse-ditto/ditto-javascript-client-node versions 2.0.0 through 3.9.0 and the predecessor @eclipse-ditto/ditto-javascript-client-node_1.0 versions 1.0.0 through 2.1.0. The Java client, browser/DOM JavaScript client, and HTTP transport of the Node.js client are not affected.

Risk and Exploitability

With a CVSS score of 9.2 the vulnerability is considered critical. Although EPSS data is not available, the absence of KEV listing does not reduce the risk: the flaw can be exploited remotely by any entity able to observe or intercept the WebSocket traffic, enabling full read/write access to the connection. Attackers could therefore exfiltrate credentials or manipulate device state without detection if TLS validation remains disabled.

Generated by OpenCVE AI on September 9, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the @eclipse-ditto/ditto-javascript-client-node package to the latest release that enforces server certificate validation if such a release exists.
  • Deploy a TLS-terminating reverse proxy to validate certificates before traffic reaches the client.
  • Restrict outgoing WebSocket connections to trusted endpoints and monitor TLS handshake anomalies.

Generated by OpenCVE AI on September 9, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse ditto
Vendors & Products Eclipse
Eclipse ditto

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Disabled TLS Validation in Eclipse Ditto Node.js Client Enables Man‑in‑the‑Middle Attacks

Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.
Weaknesses CWE-295
CWE-297
CWE-300
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-09T20:51:34.483Z

Reserved: 2026-09-01T10:53:01.024Z

Link: CVE-2026-84197

cve-icon Vulnrichment

Updated: 2026-09-09T20:46:20.619Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:51.007

Modified: 2026-09-09T21:17:05.220

Link: CVE-2026-84197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:00:12Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-297

    Improper Validation of Certificate with Host Mismatch

  • CWE-300

    Channel Accessible by Non-Endpoint