Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-15704: CWE-863 in Eclipse Foundation Eclipse BaSyx Go Components

0
Critical
VulnerabilityCVE-2026-15704cvecve-2026-15704cwe-863cwe-284cwe-180
Published: 07/24/2026 (07/24/2026, 07:41:42 UTC)
Source: CVE Database V5
Vendor/Project: Eclipse Foundation
Product: Eclipse BaSyx Go Components

Description

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.

CVSS v3.1

Score 9.8critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

github.com/eclipse-basyx/basyx-go-components
pkg:golang/github.com/eclipse-basyx/basyx-go-components
Affected versions
<=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/24/2026, 08:36:59 UTC

Technical Analysis

In Eclipse BaSyx Go Components (<=1.0.0), the ABAC middleware and the HTTP router handle trailing slashes inconsistently. The router uses Chi's middleware.StripSlashes to normalize request paths by removing trailing slashes before dispatching to handlers. However, the ABAC middleware evaluates the original request path including the trailing slash. If the ABAC middleware does not find a matching route with the trailing slash, it passes the request onward without enforcing authorization. The router then strips the slash and executes the protected handler without the intended ABAC authorization decision or query filters. This flaw allows an unauthenticated or unauthorized attacker to bypass ABAC policies by appending a trailing slash to API routes, potentially leading to unauthorized access or modification of resources. The vulnerability affects ABAC-enabled deployments of various Eclipse BaSyx services and is resolved in version 1.0.1.

Potential Impact

An attacker without authentication or proper authorization can bypass Attribute-Based Access Control (ABAC) protections by exploiting the trailing slash inconsistency. This can lead to unauthorized read, create, update, delete, or upload operations on protected API endpoints. The vulnerability has a CVSS score of 9.8 (critical), indicating high impact on confidentiality, integrity, and availability of affected services.

Mitigation Recommendations

A fix is available in Eclipse BaSyx Go Components version 1.0.1. Users should upgrade to version 1.0.1 or later to resolve this authorization bypass vulnerability. No other mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
eclipse
Date Reserved
2026-07-14T07:09:49.542Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a6320db9c2644c7f8989b8a

Added to database: 07/24/2026, 08:22:51 UTC

Last enriched: 07/24/2026, 08:36:59 UTC

Last updated: 07/24/2026, 14:06:52 UTC

Views: 33

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses