Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-8384EXPLOITEDPATCHED
eclip · jetty

CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:

Description

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.

Affected Products

VendorProductVersions
eclipjettymaven/org.eclipse.jetty:jetty-util: >= 12.0.0, <= 12.0.34, maven/org.eclipse.jetty:jetty-util: >= 12.1.0, <= 12.1.8

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
eclipjettycert_advisory90%
mavenorg.eclipse.jetty:jetty-utilGHSA85%
realobjectspdfreactorcert_advisory90%

References

  • https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108

Related News (4 articles)

Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories41d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [mittel] Eclipse Jetty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB75d ago
CVE-2026-8384 | Eclipse Jetty up to 12.0.34/12.1.8 Path Resolution /../ path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.eclipse.jetty:jetty-util@12.0.35org.eclipse.jetty:jetty-util@12.1.9
CWECWE-647
PublishedJul 14, 2026
Last enriched75d agov2
Trending Score6
Source articles4
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9563
CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
Trending: 43
HIGHCVE-2026-10050
Digest authentication lossy encoding
Trending: 20
MEDIUMCVE-2026-6790EXP
CVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and
Trending: 15
MEDIUMCVE-2026-10051EXP
CVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
Trending: 15
HIGHCVE-2026-14336EXP
CVE-2026-14336: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 75d ago
v2Tier C75d ago

Updated affected versions to 12.0.34 and 12.1.8, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploited
via VulDB
v175d ago

Initial creation