[NEW] [medium] Eclipse Jetty: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack, bypass security measures, and disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities in Eclipse Jetty can be exploited for denial of service, security bypass, and information disclosure.
- Who is affected
- Users of Eclipse Jetty.
- Urgency
- Remediation is medium urgency due to the potential for exploitation and impact on security.
- Action
- Update to the latest version of Eclipse Jetty to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jetty
Get an email when a new Jetty advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2314
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2024-77080.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-100510.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-67900.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-83840.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-7708 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10051 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6790 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8384 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highGHSA-9299-c6m4-mjhc: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsghsa
- mediumGHSA-w7x5-g22v-xqhr: Eclipse Jetty: Path parameter traversalghsa
- mediumGHSA-7p3p-8qv8-m2vh: Eclipse Jetty: HTTP Authority/Host mismatchghsa
- mediumGHSA-f4v5-65jj-pcr2: Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsghsa
- highGHSA-2fvj-hgj9-j2gr: Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypa…ghsa
- mediumCVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolv…nvd
- mediumCVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the req…nvd
- highCVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trail…nvd
- highCVE-2024-7708: For requests that have a body, but reading the body may end up in reading 0 bytes, there is a b…nvd
Recent advisories for Eclipse Jetty
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highGHSA-9299-c6m4-mjhc: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsghsa · 2026-07-22
- mediumGHSA-w7x5-g22v-xqhr: Eclipse Jetty: Path parameter traversalghsa · 2026-07-22
- mediumGHSA-7p3p-8qv8-m2vh: Eclipse Jetty: HTTP Authority/Host mismatchghsa · 2026-07-22
- mediumGHSA-f4v5-65jj-pcr2: Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsghsa · 2026-07-22
- highGHSA-2fvj-hgj9-j2gr: Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypa…ghsa · 2026-07-22
- mediumCVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolv…nvd · 2026-07-14
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31