Critical CSRF and SSRF Vulnerability in Eclipse GlassFish: CVE-2026-12605
A critical vulnerability, CVE-2026-12605, with a CVSS score of 9.6, was discovered in Eclipse GlassFish versions 8.0.x before 8.0.4. This vulnerability combines Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF) flaws in the DownloadServlet ContentSources, allowing an attacker to leak the admin `gfresttoken` and potentially take over the Eclipse GlassFish domain. The vulnerability requires user interaction but can lead to full unauthenticated takeover of the domain. Immediate patching is recommended.