{"id":"CVE-2026-10050","title":"jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050)","summary":"A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computat…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":["CWE-303","CWE-173"],"vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces 3.30","affected":["openshift_developer_tools_and_services","build_of_apache_camel_hawtio 4","build_of_apache_camel_for_spring_boot 4","build_of_debezium 3","enterprise_linux 9","openshift_ai_rhoai","satellite 6","single_sign_on 7","streams_for_apache_kafka 2","streams_for_apache_kafka 3","amq_broker 7.13.6","amq_broker 7.14.1","openshift_dev_spaces 3.30"],"patched":["amq_broker 7.13.6","amq_broker 7.14.1","openshift_dev_spaces 3.30"],"published":"2026-07-16","updated":"2026-09-10","sourceUpdated":"2026-09-10T23:24:09+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-10050"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510732"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10050"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10050"},{"url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"},{"url":"https://github.com/jetty/jetty.project/issues/15136"},{"url":"https://github.com/jetty/jetty.project/pull/15160"},{"url":"https://github.com/jetty/jetty.project/pull/15183"},{"url":"https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"},{"url":"https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"},{"url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"},{"url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"},{"url":"https://github.com/advisories/GHSA-2fvj-hgj9-j2gr"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00483,"epssPercentile":0.40651,"aliases":["GHSA-2fvj-hgj9-j2gr"],"ecosystem":"maven","ingestedAt":"2026-07-22T23:07:32.424Z","slug":"CVE-2026-10050","body":"## Overview\n\nA flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computation for passwords does not correctly handle certain characters, leading to a weakness in how passwords are processed. A remote attacker could exploit this by crafting a specific password that generates the same internal hash as a legitimate user's password, thereby bypassing authentication and gaining unauthorized access to the victim's account.\n\n## Vendor advisories\n\n- **RHSA-2026:66545** · Red Hat · fixed in: Red Hat AMQ Broker 7.13.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66545)\n- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)\n- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Debezium 3, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), … · no fix planned: streams for Apache Kafka 3, OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json)\n\n**jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision** — rated Important by Red Hat. Released 2026-07-16, updated 2026-09-10.\n\nAffected:\n\n- OpenShift Developer Tools and Services\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat build of Debezium 3\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n- streams for Apache Kafka 3\n\nFixed:\n\n- Red Hat AMQ Broker 7.13.6\n- Red Hat AMQ Broker 7.14.1\n- Red Hat OpenShift Dev Spaces 3.30\n\nNo fix planned:\n\n- streams for Apache Kafka 3\n- OpenShift Developer Tools and Services\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat build of Debezium 3\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nNot affected:\n\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat build of Apicurio Registry 3\n- Red Hat Data Grid 8\n- Red Hat Enterprise Linux 7\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat Offline Knowledge Portal\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\n## Remediation\n\nBefore applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.\n\nThe References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66545\nBefore applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.\n\nThe References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488\nBefore applying this update, make sure all previously released errata  relevant to your system have been applied. \nFor details on how to apply this update, refer to: \nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:62260\n\nWorkarounds / mitigations:\n\n- To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass.\n\n## Package advisory (CVE-2026-10050)\n\nAffected packages:\n\n- `org.eclipse.jetty:jetty-security >= 9.4.0.v20161208, <= 9.4.58.v20250814`\n- `org.eclipse.jetty:jetty-security >= 10.0.0, <= 10.0.26`\n- `org.eclipse.jetty:jetty-security >= 11.0.0, <= 11.0.26`\n- `org.eclipse.jetty:jetty-security >= 12.0.0, <= 12.0.35`\n- `org.eclipse.jetty.ee8:jetty-ee8-security >= 12.0.0, <= 12.0.35`\n- `org.eclipse.jetty.ee9:jetty-ee9-security >= 12.0.0, <= 12.0.35`\n- `org.eclipse.jetty:jetty-security >= 12.1.0, <= 12.1.9`\n- `org.eclipse.jetty.ee8:jetty-ee8-security >= 12.1.0, <= 12.1.9`\n- `org.eclipse.jetty.ee9:jetty-ee9-security >= 12.1.0, <= 12.1.9`\n\nPatched in:\n\n- `org.eclipse.jetty:jetty-security 9.4.63`\n- `org.eclipse.jetty:jetty-security 10.0.31`\n- `org.eclipse.jetty:jetty-security 11.0.31`\n- `org.eclipse.jetty:jetty-security 12.0.36`\n- `org.eclipse.jetty.ee8:jetty-ee8-security 12.0.36`\n- `org.eclipse.jetty.ee9:jetty-ee9-security 12.0.36`\n- `org.eclipse.jetty:jetty-security 12.1.10`\n- `org.eclipse.jetty.ee8:jetty-ee8-security 12.1.10`\n- `org.eclipse.jetty.ee9:jetty-ee9-security 12.1.10`\n\nSource: https://github.com/advisories/GHSA-2fvj-hgj9-j2gr","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201434,"id":"CVE-2026-10050","ts":1789399449636,"field":"cvss","old":null,"new":"9.1"},{"seq":201433,"id":"CVE-2026-10050","ts":1789399449636,"field":"severity","old":"high","new":"critical"},{"seq":200168,"id":"CVE-2026-10050","ts":1789396926629,"field":"cvss","old":"9.1","new":null},{"seq":200167,"id":"CVE-2026-10050","ts":1789396926629,"field":"severity","old":"critical","new":"high"},{"seq":198089,"id":"CVE-2026-10050","ts":1789387949927,"field":"cvss","old":null,"new":"9.1"},{"seq":198088,"id":"CVE-2026-10050","ts":1789387949927,"field":"severity","old":"high","new":"critical"},{"seq":195885,"id":"CVE-2026-10050","ts":1789383304635,"field":"cvss","old":"9.1","new":null},{"seq":195884,"id":"CVE-2026-10050","ts":1789383304635,"field":"severity","old":"critical","new":"high"},{"seq":194814,"id":"CVE-2026-10050","ts":1789380271937,"field":"cvss","old":null,"new":"9.1"},{"seq":194813,"id":"CVE-2026-10050","ts":1789380271937,"field":"severity","old":"high","new":"critical"},{"seq":193601,"id":"CVE-2026-10050","ts":1789378166808,"field":"cvss","old":"9.1","new":null},{"seq":193600,"id":"CVE-2026-10050","ts":1789378166808,"field":"severity","old":"critical","new":"high"},{"seq":192388,"id":"CVE-2026-10050","ts":1789376190659,"field":"cvss","old":null,"new":"9.1"},{"seq":192387,"id":"CVE-2026-10050","ts":1789376190659,"field":"severity","old":"high","new":"critical"},{"seq":191175,"id":"CVE-2026-10050","ts":1789373038618,"field":"cvss","old":"9.1","new":null},{"seq":191174,"id":"CVE-2026-10050","ts":1789373038618,"field":"severity","old":"critical","new":"high"},{"seq":189960,"id":"CVE-2026-10050","ts":1789369092876,"field":"cvss","old":null,"new":"9.1"},{"seq":189959,"id":"CVE-2026-10050","ts":1789369092876,"field":"severity","old":"high","new":"critical"},{"seq":188747,"id":"CVE-2026-10050","ts":1789367989287,"field":"cvss","old":"9.1","new":null},{"seq":188746,"id":"CVE-2026-10050","ts":1789367989287,"field":"severity","old":"critical","new":"high"},{"seq":187530,"id":"CVE-2026-10050","ts":1789364941502,"field":"cvss","old":null,"new":"9.1"},{"seq":187529,"id":"CVE-2026-10050","ts":1789364941502,"field":"severity","old":"high","new":"critical"},{"seq":186317,"id":"CVE-2026-10050","ts":1789362906250,"field":"cvss","old":"9.1","new":null},{"seq":186316,"id":"CVE-2026-10050","ts":1789362906250,"field":"severity","old":"critical","new":"high"},{"seq":185103,"id":"CVE-2026-10050","ts":1789360928803,"field":"cvss","old":null,"new":"9.1"},{"seq":185102,"id":"CVE-2026-10050","ts":1789360928803,"field":"severity","old":"high","new":"critical"},{"seq":183890,"id":"CVE-2026-10050","ts":1789357850871,"field":"cvss","old":"9.1","new":null},{"seq":183889,"id":"CVE-2026-10050","ts":1789357850871,"field":"severity","old":"critical","new":"high"},{"seq":182142,"id":"CVE-2026-10050","ts":1789354054467,"field":"cvss","old":null,"new":"9.1"},{"seq":182141,"id":"CVE-2026-10050","ts":1789354054467,"field":"severity","old":"high","new":"critical"},{"seq":180935,"id":"CVE-2026-10050","ts":1789352878355,"field":"cvss","old":"9.1","new":null},{"seq":180934,"id":"CVE-2026-10050","ts":1789352878355,"field":"severity","old":"critical","new":"high"},{"seq":179728,"id":"CVE-2026-10050","ts":1789349951376,"field":"cvss","old":null,"new":"9.1"},{"seq":179727,"id":"CVE-2026-10050","ts":1789349951376,"field":"severity","old":"high","new":"critical"},{"seq":178521,"id":"CVE-2026-10050","ts":1789347713468,"field":"cvss","old":"9.1","new":null},{"seq":178520,"id":"CVE-2026-10050","ts":1789347713468,"field":"severity","old":"critical","new":"high"},{"seq":177314,"id":"CVE-2026-10050","ts":1789346134054,"field":"cvss","old":null,"new":"9.1"},{"seq":177313,"id":"CVE-2026-10050","ts":1789346134054,"field":"severity","old":"high","new":"critical"},{"seq":176107,"id":"CVE-2026-10050","ts":1789342648149,"field":"cvss","old":"9.1","new":null},{"seq":176106,"id":"CVE-2026-10050","ts":1789342648149,"field":"severity","old":"critical","new":"high"},{"seq":175893,"id":"CVE-2026-10050","ts":1789342261540,"field":"cvss","old":null,"new":"9.1"},{"seq":175892,"id":"CVE-2026-10050","ts":1789342261540,"field":"severity","old":"high","new":"critical"},{"seq":175431,"id":"CVE-2026-10050","ts":1789338286138,"field":"cvss","old":"9.1","new":null},{"seq":175430,"id":"CVE-2026-10050","ts":1789338286138,"field":"severity","old":"critical","new":"high"},{"seq":174226,"id":"CVE-2026-10050","ts":1789334561098,"field":"cvss","old":null,"new":"9.1"},{"seq":174225,"id":"CVE-2026-10050","ts":1789334561098,"field":"severity","old":"high","new":"critical"},{"seq":173021,"id":"CVE-2026-10050","ts":1789333122996,"field":"cvss","old":"9.1","new":null},{"seq":173020,"id":"CVE-2026-10050","ts":1789333122996,"field":"severity","old":"critical","new":"high"},{"seq":171835,"id":"CVE-2026-10050","ts":1789330837582,"field":"cvss","old":null,"new":"9.1"},{"seq":171834,"id":"CVE-2026-10050","ts":1789330837582,"field":"severity","old":"high","new":"critical"}]}