CVE-2026-5795High· 7.4▾ TwilightIn Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.
A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.
jetty >= 9.4.0, <= 9.4.58jetty >= 10.0.0, <= 10.0.26jetty >= 11.0.0, <= 11.0.26jetty >= 12.0.0, < 12.0.34jetty >= 12.1.0, < 12.1.8Upgrade past the affected range:
jetty 12.1.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2332High· 7.4In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…
CVE-2026-1605High· 7.5In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This hap…
CVE-2026-42041Medium· 4.8Axios is a promise based HTTP client for the browser and Node.js
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-19607Medium· 5.3A flaw was found in the first-broker-login flow of the keycloak-services component
CVE-2026-18922Critical· 9.8A flaw was found in 389 Directory Server