CVE-2026-10050Critical· 9.1▾ MidnightA flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computat…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
0.4% → 0.5%
Last analysed / modified upstream
9.1 → —
critical → high
— → 9.1
high → critical
9.1 → —
critical → high
— → 9.1
high → critical
9.1 → —
critical → high
— → 9.1
high → critical
A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computation for passwords does not correctly handle certain characters, leading to a weakness in how passwords are processed. A remote attacker could exploit this by crafting a specific password that generates the same internal hash as a legitimate user's password, thereby bypassing authentication and gaining unauthorized access to the victim's account.
jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision — rated Important by Red Hat. Released 2026-07-16, updated 2026-09-10.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.
The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66545 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.
The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:62260
Workarounds / mitigations:
Affected packages:
org.eclipse.jetty:jetty-security >= 9.4.0.v20161208, <= 9.4.58.v20250814org.eclipse.jetty:jetty-security >= 10.0.0, <= 10.0.26org.eclipse.jetty:jetty-security >= 11.0.0, <= 11.0.26org.eclipse.jetty:jetty-security >= 12.0.0, <= 12.0.35org.eclipse.jetty.ee8:jetty-ee8-security >= 12.0.0, <= 12.0.35org.eclipse.jetty.ee9:jetty-ee9-security >= 12.0.0, <= 12.0.35org.eclipse.jetty:jetty-security >= 12.1.0, <= 12.1.9org.eclipse.jetty.ee8:jetty-ee8-security >= 12.1.0, <= 12.1.9org.eclipse.jetty.ee9:jetty-ee9-security >= 12.1.0, <= 12.1.9Patched in:
org.eclipse.jetty:jetty-security 9.4.63org.eclipse.jetty:jetty-security 10.0.31org.eclipse.jetty:jetty-security 11.0.31org.eclipse.jetty:jetty-security 12.0.36org.eclipse.jetty.ee8:jetty-ee8-security 12.0.36org.eclipse.jetty.ee9:jetty-ee9-security 12.0.36org.eclipse.jetty:jetty-security 12.1.10org.eclipse.jetty.ee8:jetty-ee8-security 12.1.10org.eclipse.jetty.ee9:jetty-ee9-security 12.1.10Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55831High· 7.5io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831)
CVE-2026-55833High· 7.5netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833)
CVE-2026-56745High· 7.5netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745)
CVE-2026-56746High· 7.5io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)
CVE-2026-59899High· 7.5io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)
CVE-2026-56819High· 7.5io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)