Executive brief
Eclipse Kura, an open-source framework for IoT gateways, contains a flaw that allows attackers to fake their network location. By manipulating technical headers in web requests, an attacker can hide their true identity from security logs or trick the system into blocking innocent third parties. This can be used to bypass security protections that prevent password guessing or to disrupt service for legitimate users.
Technical details
Eclipse Kura (versions 5.0.0 through 5.6.1) incorrectly trusts the 'X-Forwarded-For' HTTP header as the authoritative source for client IP addresses. The vulnerability exists because the 'org.eclipse.kura.jetty.customizer' component unconditionally installs Jetty's 'ForwardedRequestCustomizer', which causes 'HttpServletRequest.getRemoteAddr()' to return attacker-controlled values. This affects the Web Console and REST API components. An unauthenticated remote attacker can exploit this to bypass IP-based rate limiting (like fail2ban) by spoofing non-routable IPs, or perform a Denial of Service (DoS) by spoofing a victim's IP to trigger an automated ban. The issue is resolved in version 5.6.2.
Affected products
- Eclipse Foundation Kura 5.0.0 to 5.6.1
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: disclosed: Initial CVE publication
- 2026-07-14: patched: Version 5.6.2 released