cbcvebase.
CVE-2026-8384
published 2026-07-14

CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected…

PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.33%
25.9th percentile
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpuppetserver
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
eclipsejetty>= 12.0.0 < 12.0.3512.0.35
eclipsejetty>= 12.1.0 < 12.1.912.1.9
eclipse_foundationeclipse_jetty12.0.0 – 12.0.34
eclipse_foundationeclipse_jetty12.1.0 – 12.1.8
jenkinsjenkins
ocp-tools-4jenkins-rhel8
ocp-tools-4jenkins-rhel9
offline-knowledge-portalrhokp-rhel9
rhoaiodh-spark-operator-rhel9
rhoaiodh-th06-cpu-torch210-py312-rhel9
rhoaiodh-th06-cpu-torch291-py312-rhel9
rhoaiodh-th06-cuda130-torch210-py312-rhel9
rhoaiodh-th06-cuda130-torch291-py312-rhel9
rhoaiodh-th06-rocm64-torch291-py312-rhel9
satellite-capsule_el8puppetserver

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.