CRITICAL 9.6 NVD
CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
References
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-08-06 via NVD.
Risk Timeline
CVE Disclosed2026-08-06 · -1 days ago
Remediation Resources
Official Advisory
gitlab.eclipse.org/security/cve-assignment/-/work_items/127Official Advisory
gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445
vulnfeed aggregates 9341 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.