Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-10050PATCHED
eclip · jetty

Digest authentication lossy encoding

Description

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

Affected Products

VendorProductVersions
eclipjettymaven/org.eclipse.jetty:jetty-security: >= 9.4.0.v20161208, <= 9.4.58.v20250814, maven/org.eclipse.jetty:jetty-security: >= 10.0.0, <= 10.0.26, maven/org.eclipse.jetty:jetty-security: >= 11.0.0, <= 11.0.26, maven/org.eclipse.jetty:jetty-security: >= 12.0.0, <= 12.0.35, maven/org.eclipse.jetty.ee8:jetty-ee8-security: >= 12.0.0, <= 12.0.35, maven/org.eclipse.jetty.ee9:jetty-ee9-security: >= 12.0.0, <= 12.0.35, maven/org.eclipse.jetty:jetty-security: >= 12.1.0, <= 12.1.9, maven/org.eclipse.jetty.ee8:jetty-ee8-security: >= 12.1.0, <= 12.1.9, maven/org.eclipse.jetty.ee9:jetty-ee9-security: >= 12.1.0, <= 12.1.9

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassianfisheyecert_advisory90%
atlassianconfluencecert_advisory90%
atlassiancruciblecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianjiracert_advisory90%

References

  • https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr
  • https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120

Related News (6 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories39d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories41d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier C
VulDB54d ago
CVE-2026-10050 | Eclipse Jetty Digest Authentication Server-side improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
org.eclipse.jetty:jetty-security@9.4.63org.eclipse.jetty:jetty-security@10.0.31org.eclipse.jetty:jetty-security@11.0.31org.eclipse.jetty:jetty-security@12.0.36org.eclipse.jetty.ee8:jetty-ee8-security@12.0.36org.eclipse.jetty.ee9:jetty-ee9-security@12.0.36org.eclipse.jetty:jetty-security@12.1.10org.eclipse.jetty.ee8:jetty-ee8-security@12.1.10org.eclipse.jetty.ee9:jetty-ee9-security@12.1.10
CWECWE-173, CWE-303
PublishedJul 22, 2026
Tags
GHSA-2fvj-hgj9-j2grmaven
Trending Score20
Source articles6
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9563
CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
Trending: 43
MEDIUMCVE-2026-6790EXP
CVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and
Trending: 15
MEDIUMCVE-2026-10051EXP
CVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
Trending: 15
MEDIUMCVE-2026-8384EXP
CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
Trending: 6
HIGHCVE-2026-14336EXP
CVE-2026-14336: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Patch Available
Aug 4, 2026