[UPDATE] [mittel] Eclipse Jetty: Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.
CSIRTS triage
- What
- Multiple vulnerabilities in Eclipse Jetty can be exploited for denial of service, security bypass, and information disclosure.
- Who is affected
- Users of Eclipse Jetty.
- Urgency
- Remediation is medium urgency due to the potential for exploitation and impact on security.
- Action
- Update to the latest version of Eclipse Jetty to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jetty
Get an email when a new Jetty advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2314
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2024-77080.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-100500.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-100510.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67900.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-83840.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-7708 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10051 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6790 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8384 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownNCSC-2026-0325 [1.00] [M/H] Kwetsbaarheden verholpen in Atlassian productenncsc-nl
- medium[NEW] [medium] RealObjects PDFreactor: Multiple vulnerabilities enable unspecified attackcert-bund
- criticalCVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode th…nvd
- highGHSA-9299-c6m4-mjhc: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsghsa
- mediumGHSA-w7x5-g22v-xqhr: Eclipse Jetty: Path parameter traversalghsa
- mediumGHSA-7p3p-8qv8-m2vh: Eclipse Jetty: HTTP Authority/Host mismatchghsa
- mediumGHSA-f4v5-65jj-pcr2: Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsghsa
- highGHSA-2fvj-hgj9-j2gr: Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypa…ghsa
- mediumCVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolv…nvd
- mediumCVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the req…nvd
Recent advisories for Eclipse Jetty
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEU] [mittel] Eclipse Jetty: Schwachstelle ermöglicht Denial of Servicecert-bund · 2026-09-08
- medium[UPDATE] [medium] Eclipse Jetty: Vulnerability allows data manipulationcert-bund · 2026-08-27
- medium[UPDATE] [medium] Eclipse Jetty: Vulnerability allows Denial of Servicecert-bund · 2026-08-27
- low[UPDATE] [low] Eclipse Jetty: Vulnerability allows bypassing of security measurescert-bund · 2026-08-14
- criticalCVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode th…nvd · 2026-08-04
- highGHSA-9299-c6m4-mjhc: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsghsa · 2026-07-22
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11