web
A containerized Eclipse Jetty 12.0.36 server built from the official distribution with SHA-256 verification. It serves a web application with a DIGEST-protected resource at /protected/*, using a HashLoginService realm with a victim account whose password contains non-ISO-8859-1 characters. The patched version is expected to reject the colliding password attack.
CVE-2026-10050/docker-compose.control.yml:2-14CVE-2026-10050/Dockerfile.patched:1-27CVE-2026-10050/jetty-base/webapps/ROOT/WEB-INF/web.xml:1-28CVE-2026-10050/jetty-base/etc/realm.properties:1-7