Eclipse ditto
This hub aggregates every CVE we track for Eclipse ditto, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Eclipse ditto.
- CVE-2026-84197In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript...
- CVE-2026-82958In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_i...
- CVE-2026-84175In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without...
- CVE-2024-5165Eclipse Ditto User Interface vulnerable to XSS due to Improper Neutralization of Input6.5
Product normalization is registry-driven with AI assist and human review. How it works