Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-14336EXPLOITEDPATCHED
eclip · pia

CVE-2026-14336: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

Description

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attacker controls. An unauthenticated caller of POST /v1/upload/sbom can use this to force PIA to make outbound HTTP(S) requests to an arbitrary attacker-chosen host, and to have oidc.verify_token accept a JWT signed with the attacker's own key.

Affected Products

VendorProductVersions
eclippia0

References

  • https://gitlab.eclipse.org/security/cve-assignment/-/work_items/154

Related News (1 articles)

Tier C
VulDB87d ago
CVE-2026-14336 | Eclipse CSI up to 0.3.0 server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
0.3.0
CWECWE-918
PublishedJul 2, 2026
Last enriched87d agov2
Tags
server-side request forgery
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9563
CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
Trending: 43
HIGHCVE-2026-10050
Digest authentication lossy encoding
Trending: 20
MEDIUMCVE-2026-6790EXP
CVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and
Trending: 15
MEDIUMCVE-2026-10051EXP
CVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
Trending: 15
MEDIUMCVE-2026-8384EXP
CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 2, 2026
Discovered by ZDM
Jul 2, 2026
Updated: severity, activelyExploited, patchAvailable, tags
Jul 2, 2026
Actively Exploited
Jul 2, 2026
Patch Available
Jul 2, 2026

Version History

v2
Last enriched 87d ago
v2Tier C87d ago

Updated severity to CRITICAL, marked as actively exploited, and added patch version 0.3.0 along with new tag for server-side request forgery.

severityactivelyExploitedpatchAvailabletags
via VulDB
v187d ago

Initial creation