cbcvebase.
CVE-2026-10050
published 2026-08-04

CVE-2026-10050: In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial…

PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.48%
39.8th percentile
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
eclipsejetty>= 10.0.0 < 10.0.3110.0.31
eclipsejetty>= 11.0.0 < 11.0.3111.0.31
eclipsejetty>= 12.0.0 < 12.0.3612.0.36
eclipsejetty>= 12.1.0 < 12.1.1012.1.10
eclipsejetty>= 9.4.0 < 9.4.639.4.63
eclipse_foundationeclipse_jetty10.0.0 – 10.0.30
eclipse_foundationeclipse_jetty11.0.0 – 11.0.30
eclipse_foundationeclipse_jetty12.0.0 – 12.0.35
eclipse_foundationeclipse_jetty12.1.0 – 12.1.9
eclipse_foundationeclipse_jetty9.4.0 – 9.4.62
eclipse_foundationeclipse_jetty_ee812.0.0 – 12.0.35
eclipse_foundationeclipse_jetty_ee812.1.0 – 12.1.9
eclipse_foundationeclipse_jetty_ee912.0.0 – 12.0.35
eclipse_foundationeclipse_jetty_ee912.1.0 – 12.1.9
jenkinsjenkins
ocp-tools-4jenkins-rhel8
ocp-tools-4jenkins-rhel9
offline-knowledge-portalrhokp-rhel9
rhoaiodh-spark-operator-rhel9
rhoaiodh-th06-cpu-torch210-py312-rhel9
rhoaiodh-th06-cpu-torch291-py312-rhel9
rhoaiodh-th06-cuda130-torch210-py312-rhel9
rhoaiodh-th06-cuda130-torch291-py312-rhel9

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.