Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-6790EXPLOITEDPATCHED
eclip · jetty

CVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and

Description

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112). This mismatch can cause a number of problems that may be classified as vulnerabilities such as: * URI constructions (for example, for redirects -- this is typical for login pages) * Virtual host selection * Reverse proxying * Misleading logs * Etc. Given that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.

Affected Products

VendorProductVersions
eclipjettymaven/org.eclipse.jetty:jetty-server: >= 9.4.0.v20161208, <= 9.4.58.v20250814, maven/org.eclipse.jetty:jetty-server: >= 10.0.0, <= 10.0.26, maven/org.eclipse.jetty:jetty-server: >= 11.0.0, <= 11.0.26, maven/org.eclipse.jetty:jetty-server: >= 12.0.0, <= 12.0.34, maven/org.eclipse.jetty:jetty-server: >= 12.1.0, <= 12.1.8

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
eclipjettycert_advisory90%
mavenorg.eclipse.jetty:jetty-serverGHSA85%
realobjectspdfreactorcert_advisory90%

References

  • https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99

Related News (6 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories41d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [mittel] Eclipse Jetty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB75d ago
CVE-2026-6790 | Eclipse Jetty up to 12.1.8 Authority input validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.eclipse.jetty:jetty-server@12.0.35org.eclipse.jetty:jetty-server@12.1.9
CWECWE-20
PublishedJul 14, 2026
Last enriched75d agov2
Trending Score15
Source articles6
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9563
CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
Trending: 43
HIGHCVE-2026-10050
Digest authentication lossy encoding
Trending: 20
MEDIUMCVE-2026-10051EXP
CVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
Trending: 15
MEDIUMCVE-2026-8384EXP
CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
Trending: 6
HIGHCVE-2026-14336EXP
CVE-2026-14336: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 75d ago
v2Tier C75d ago

Updated affected versions to include 9.4.60, 10.0.28, 11.0.28, 12.0.34, and changed severity to CRITICAL.

affectedVersionsseverityactivelyExploited
via VulDB
v175d ago

Initial creation