CVE-2026-84197
Deferred Deferred - Pending Action

Prototype Pollution in Eclipse Ditto Node.js Client

Vulnerability report for CVE-2026-84197, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: Eclipse Foundation

Description

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
eclipse ditto_javascript_client_node From 2.0.0 (inc) to 3.9.0 (inc)
eclipse ditto_javascript_client_node_1.0 From 1.0.0 (inc) to 2.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-297 The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
CWE-300 The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Eclipse Ditto's Node.js JavaScript client packages @eclipse-ditto/ditto-javascript-client-node (versions 2.0.0 to 3.9.0) and @eclipse-ditto/ditto-javascript-client-node_1.0 (versions 1.0.0 to 2.1.0). The WebSocket transport in these packages hard-codes rejectUnauthorized: false, disabling TLS certificate chain and hostname validation for wss:// connections. This allows attackers to intercept connections, read credentials in Authorization headers, and manipulate Ditto Protocol messages.

Detection Guidance

Check if your application uses the affected Node.js JavaScript client packages (@eclipse-ditto/ditto-javascript-client-node versions 2.0.0 to 3.9.0 or @eclipse-ditto/ditto-javascript-client-node_1.0 versions 1.0.0 to 2.1.0). Inspect WebSocket connections for hardcoded rejectUnauthorized: false settings. Monitor network traffic for unencrypted or intercepted TLS connections.

Impact Analysis

If you use affected versions of the Eclipse Ditto Node.js JavaScript client with WebSocket connections, an attacker could intercept your connection, steal credentials sent in Authorization headers, and read or alter messages exchanged with the Ditto server. This could lead to unauthorized access to data or system control.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and secure communication, such as GDPR's encryption mandates and HIPAA's transmission security rules. The lack of TLS validation exposes sensitive data in transit, potentially leading to unauthorized access and data breaches.

Mitigation Strategies

Upgrade to the latest patched version of the affected packages if available. Switch from WebSocket transport to HTTP transport if possible. Implement custom TLS validation in your application code as a workaround. Avoid using wss:// connections until the issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84197. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart