CVE-2026-10051Medium· 5.3▾ SunlitA flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.4%
Last analysed / modified upstream
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintentionally disclose information by reporting the previously retained trailers, or a combination of previous and current request trailers.
jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections — rated Moderate by Red Hat. Released 2026-07-14, updated 2026-09-10.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For detailed instructions how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63327 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For detailed instructions how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63387 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:63386
Workarounds / mitigations:
Affected packages:
org.eclipse.jetty:jetty-server >= 12.0.0, <= 12.0.35org.eclipse.jetty:jetty-server >= 12.1.0, <= 12.1.9Patched in:
org.eclipse.jetty:jetty-server 12.0.36org.eclipse.jetty:jetty-server 12.1.10Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-38554Medium· 5.3vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)
CVE-2025-22866Medium· 5.3crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
CVE-2025-2842Medium· 4.3A flaw was found in the Tempo Operator
CVE-2025-2786Medium· 4.3A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance
CVE-2026-95897Medium· 5.5A security vulnerability has been detected in Dask up to 2026.8.0
CVE-2026-13087High· 8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c