Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-84197: Eclipse Ditto Node client disables TLS certificate checks

CVE-2026-84197 · published 1 month ago
Summary

The Node.js client for Eclipse Ditto does not verify server certificates when using secure WebSocket connections, allowing anyone who can intercept the traffic to see or change the data being sent. This issue affects all released versions of the client library. Update to a version that restores proper certificate validation or switch to a different transport method such as HTTP or the browser client.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
eclipse foundation eclipse ditto < 3.8.1
<= 2.1.0
Original advisory text
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript...
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
CWE-297Improper Validation of Certificate with Host Mismatch
CWE-300Channel Accessible by Non-Endpoint
Timeline
Published8 Sep 2026
Updated7 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-84197 · MITRE
Track software like this
Free during beta