CVE-2026-10051

HIGH

Eclipse Jetty - Exposure of Sensitive Information to an Unauthorized Actor

Title source: rule
STIX 2.1

Description

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (5)
eclipse/jetty 12.0.0 - 12.0.36
Eclipse Foundation/Eclipse Jetty 12.0.0 - 12.0.35
Eclipse Foundation/Eclipse Jetty 12.1.0 - 12.1.9
org.eclipse.jetty/jetty-server 12.0.0 - 12.0.36Maven
org.eclipse.jetty/jetty-server 12.1.0 - 12.1.10Maven
Published Jul 14, 2026
Tracked Since Jul 14, 2026