---
id: CVE-2026-10050
title: >-
  jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication
  encoding collision (CVE-2026-10050)
summary: >-
  A flaw was found in Eclipse Jetty, a widely used web server and servlet
  container. This vulnerability affects its HTTP Digest authentication
  mechanism, which is used to verify user identities. The issue arises because
  Jetty's hash computat…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-303
  - CWE-173
vendor: Red Hat
product: Red Hat OpenShift Dev Spaces 3.30
affected:
  - openshift_developer_tools_and_services
  - build_of_apache_camel_hawtio 4
  - build_of_apache_camel_for_spring_boot 4
  - build_of_debezium 3
  - enterprise_linux 9
  - openshift_ai_rhoai
  - satellite 6
  - single_sign_on 7
  - streams_for_apache_kafka 2
  - streams_for_apache_kafka 3
  - amq_broker 7.13.6
  - amq_broker 7.14.1
  - openshift_dev_spaces 3.30
patched:
  - amq_broker 7.13.6
  - amq_broker 7.14.1
  - openshift_dev_spaces 3.30
published: '2026-07-16'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T23:24:09+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-10050'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510732'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-10050'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10050'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66545'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
  - url: >-
      https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr
  - url: 'https://github.com/jetty/jetty.project/issues/15136'
  - url: 'https://github.com/jetty/jetty.project/pull/15160'
  - url: 'https://github.com/jetty/jetty.project/pull/15183'
  - url: >-
      https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d
  - url: >-
      https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d
  - url: 'https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36'
  - url: 'https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10'
  - url: 'https://github.com/advisories/GHSA-2fvj-hgj9-j2gr'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.00483
epssPercentile: 0.40797
aliases:
  - GHSA-2fvj-hgj9-j2gr
ecosystem: maven
ingestedAt: '2026-07-22T23:07:32.424Z'
---

## Overview

A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computation for passwords does not correctly handle certain characters, leading to a weakness in how passwords are processed. A remote attacker could exploit this by crafting a specific password that generates the same internal hash as a legitimate user's password, thereby bypassing authentication and gaining unauthorized access to the victim's account.

## Vendor advisories

- **RHSA-2026:66545** · Red Hat · fixed in: Red Hat AMQ Broker 7.13.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66545)
- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)
- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)
- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Debezium 3, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), … · no fix planned: streams for Apache Kafka 3, OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10050.json)

**jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision** — rated Important by Red Hat. Released 2026-07-16, updated 2026-09-10.

Affected:

- OpenShift Developer Tools and Services
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Debezium 3
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Single Sign-On 7
- streams for Apache Kafka 2
- streams for Apache Kafka 3

Fixed:

- Red Hat AMQ Broker 7.13.6
- Red Hat AMQ Broker 7.14.1
- Red Hat OpenShift Dev Spaces 3.30

No fix planned:

- streams for Apache Kafka 3
- OpenShift Developer Tools and Services
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Debezium 3
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Single Sign-On 7
- streams for Apache Kafka 2

Not affected:

- Red Hat OpenShift Dev Spaces 3.30
- Red Hat build of Apicurio Registry 3
- Red Hat Data Grid 8
- Red Hat Enterprise Linux 7
- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Offline Knowledge Portal
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

## Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.

The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66545
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.

The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488
Before applying this update, make sure all previously released errata  relevant to your system have been applied. 
For details on how to apply this update, refer to: 
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:62260

Workarounds / mitigations:

- To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass.

## Package advisory (CVE-2026-10050)

Affected packages:

- `org.eclipse.jetty:jetty-security >= 9.4.0.v20161208, <= 9.4.58.v20250814`
- `org.eclipse.jetty:jetty-security >= 10.0.0, <= 10.0.26`
- `org.eclipse.jetty:jetty-security >= 11.0.0, <= 11.0.26`
- `org.eclipse.jetty:jetty-security >= 12.0.0, <= 12.0.35`
- `org.eclipse.jetty.ee8:jetty-ee8-security >= 12.0.0, <= 12.0.35`
- `org.eclipse.jetty.ee9:jetty-ee9-security >= 12.0.0, <= 12.0.35`
- `org.eclipse.jetty:jetty-security >= 12.1.0, <= 12.1.9`
- `org.eclipse.jetty.ee8:jetty-ee8-security >= 12.1.0, <= 12.1.9`
- `org.eclipse.jetty.ee9:jetty-ee9-security >= 12.1.0, <= 12.1.9`

Patched in:

- `org.eclipse.jetty:jetty-security 9.4.63`
- `org.eclipse.jetty:jetty-security 10.0.31`
- `org.eclipse.jetty:jetty-security 11.0.31`
- `org.eclipse.jetty:jetty-security 12.0.36`
- `org.eclipse.jetty.ee8:jetty-ee8-security 12.0.36`
- `org.eclipse.jetty.ee9:jetty-ee9-security 12.0.36`
- `org.eclipse.jetty:jetty-security 12.1.10`
- `org.eclipse.jetty.ee8:jetty-ee8-security 12.1.10`
- `org.eclipse.jetty.ee9:jetty-ee9-security 12.1.10`

Source: https://github.com/advisories/GHSA-2fvj-hgj9-j2gr
