CVE-2026-15704: CWE-863 in Eclipse Foundation Eclipse BaSyx Go Components
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.
AI Analysis
Technical Summary
In Eclipse BaSyx Go Components (<=1.0.0), the ABAC middleware and the HTTP router handle trailing slashes inconsistently. The router uses Chi's middleware.StripSlashes to normalize request paths by removing trailing slashes before dispatching to handlers. However, the ABAC middleware evaluates the original request path including the trailing slash. If the ABAC middleware does not find a matching route with the trailing slash, it passes the request onward without enforcing authorization. The router then strips the slash and executes the protected handler without the intended ABAC authorization decision or query filters. This flaw allows an unauthenticated or unauthorized attacker to bypass ABAC policies by appending a trailing slash to API routes, potentially leading to unauthorized access or modification of resources. The vulnerability affects ABAC-enabled deployments of various Eclipse BaSyx services and is resolved in version 1.0.1.
Potential Impact
An attacker without authentication or proper authorization can bypass Attribute-Based Access Control (ABAC) protections by exploiting the trailing slash inconsistency. This can lead to unauthorized read, create, update, delete, or upload operations on protected API endpoints. The vulnerability has a CVSS score of 9.8 (critical), indicating high impact on confidentiality, integrity, and availability of affected services.
Mitigation Recommendations
A fix is available in Eclipse BaSyx Go Components version 1.0.1. Users should upgrade to version 1.0.1 or later to resolve this authorization bypass vulnerability. No other mitigation steps are indicated by the vendor advisory.
CVE-2026-15704: CWE-863 in Eclipse Foundation Eclipse BaSyx Go Components
Description
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.
CVSS v3.1
Score 9.8critical
Affected software
pkg:golang/github.com/eclipse-basyx/basyx-go-componentsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Eclipse BaSyx Go Components (<=1.0.0), the ABAC middleware and the HTTP router handle trailing slashes inconsistently. The router uses Chi's middleware.StripSlashes to normalize request paths by removing trailing slashes before dispatching to handlers. However, the ABAC middleware evaluates the original request path including the trailing slash. If the ABAC middleware does not find a matching route with the trailing slash, it passes the request onward without enforcing authorization. The router then strips the slash and executes the protected handler without the intended ABAC authorization decision or query filters. This flaw allows an unauthenticated or unauthorized attacker to bypass ABAC policies by appending a trailing slash to API routes, potentially leading to unauthorized access or modification of resources. The vulnerability affects ABAC-enabled deployments of various Eclipse BaSyx services and is resolved in version 1.0.1.
Potential Impact
An attacker without authentication or proper authorization can bypass Attribute-Based Access Control (ABAC) protections by exploiting the trailing slash inconsistency. This can lead to unauthorized read, create, update, delete, or upload operations on protected API endpoints. The vulnerability has a CVSS score of 9.8 (critical), indicating high impact on confidentiality, integrity, and availability of affected services.
Mitigation Recommendations
A fix is available in Eclipse BaSyx Go Components version 1.0.1. Users should upgrade to version 1.0.1 or later to resolve this authorization bypass vulnerability. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-07-14T07:09:49.542Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6320db9c2644c7f8989b8a
Added to database: 07/24/2026, 08:22:51 UTC
Last enriched: 07/24/2026, 08:36:59 UTC
Last updated: 07/24/2026, 14:06:52 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.