CVE-2026-10050

CVE-2026-10050 is a high-severity security vulnerability in org.eclipse.jetty:jetty-security (maven), affecting versions >= 9.4.0.v20161208, <= 9.4.58.v20250814. It is fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

The DigestAuthentication.apply() method in Jetty's HTTP client uses getBytes(StandardCharsets.ISO_8859_1) at three locations (lines 171, 179, 196) to compute Digest auth response hashes. ISO-8859-1 silently replaces any character above U+00FF (Chinese, Japanese, Cyrillic, Arabic, Emoji, etc.) with 0x3F (?), causing all such characters to produce identical hash contributions. An attacker who knows a victim's username can bypass Digest authentication by replacing all non-Latin-1 characters in the password with ? characters, since the collision password produces the same MD5-based Digest response hash as the original password.

Details

Root Cause

In jetty-core/jetty-client/src/main/java/org/eclipse/jetty/client/DigestAuthentication.java, the apply() method computes the three Digest auth hashes (H(A1), H(A2), and the final response) using ISO-8859-1 character encoding:

// Line 171, H(A1)
String hashA1 = toHexString(digester.digest(a1.getBytes(StandardCharsets.ISO_8859_1)));

// Line 179, H(A2)
String hashA2 = toHexString(digester.digest(a2.getBytes(StandardCharsets.ISO_8859_1)));

// Line 196, Final response hash
final String hashA3 = toHexString(digester.digest(a3.getBytes(StandardCharsets.ISO_8859_1)));

ISO-8859-1 (Latin-1) can only encode characters in the range U+0000–U+00FF. Any character outside this range, including all CJK, Cyrillic, Arabic, Greek, Hangul, and emoji characters, is silently replaced with the byte 0x3F (?). String.getBytes(ISO_8859_1) in Java performs this replacement without any warning or exception.

PoC

Password: "我爱Java!密码123★" (7 non-Latin-1 characters)

UTF-8 encoding:    45 bytes → MD5 H(A1) = 9a4e61484f228633d5d0f95d1bbb0a99
ISO-8859-1:        31 bytes → MD5 H(A1) = d60ddc903d71913bcc3ab4a94f7fc239
Collision "??...": 31 bytes → MD5 H(A1) = d60ddc903d71913bcc3ab4a94f7fc239 ← IDENTICAL

Multi-language confirmation, all four language passwords below produce the same hash:

Chinese (密码123)  → H(A1) = db87f31e8d96cd15f9acec7eabdc4560
Korean  (비번123)  → H(A1) = db87f31e8d96cd15f9acec7eabdc4560
Cyrillic(аб123)    → H(A1) = db87f31e8d96cd15f9acec7eabdc4560
Greek   (αβ123)    → H(A1) = db87f31e8d96cd15f9acec7eabdc4560
Attacker(??123)    → H(A1) = db87f31e8d96cd15f9acec7eabdc4560 ← all collide!

Impact

Scenario 1: Authentication Bypass (Collision Attack)

If a service using Jetty for Digest authentication has a user with a non-Latin-1 password (e.g., Chinese, Japanese, Russian), an attacker can authenticate as that user using a collision password where all non-Latin-1 characters are replaced with ?:

  • Original password: 我爱Java!密码123★
  • Collision password: ??Java!??123?
  • Both produce identical MD5 hashes under ISO-8859-1 → Authentication succeeds

This affects any password containing characters > U+00FF, which covers:

  • Chinese (CJK): U+4E00–U+9FFF
  • Japanese (Hiragana/Katakana/Kanji): U+3040–U+30FF, U+4E00+
  • Korean (Hangul): U+AC00–U+D7AF
  • Cyrillic: U+0400–U+04FF (Russian, Ukrainian, Bulgarian, etc.)
  • Arabic: U+0600–U+06FF
  • Greek: U+0370–U+03FF
  • Latin Extended: U+0100–U+024F (accented European characters like ĉ, ğ, ñ when > U+00FF)
  • Emoji / Symbols > U+00FF

Scenario 2: Denial of Service for Non-Latin-1 Users

Most modern web applications store password hashes computed using UTF-8. When Jetty's Digest client computes a hash with ISO-8859-1, the bytes differ from what the server stored/expects. This means any user with non-ASCII (Latin-1+) characters in their password can never successfully authenticate via Digest auth, even the legitimate user. This is not just a security issue but a functional correctness bug that silently breaks authentication for most non-European-language users.

Affected versions

org.eclipse.jetty:jetty-security (>= 9.4.0.v20161208, <= 9.4.58.v20250814) org.eclipse.jetty:jetty-security (>= 10.0.0, <= 10.0.26) org.eclipse.jetty:jetty-security (>= 11.0.0, <= 11.0.26) org.eclipse.jetty:jetty-security (>= 12.0.0, <= 12.0.35) org.eclipse.jetty.ee8:jetty-ee8-security (>= 12.0.0, <= 12.0.35) org.eclipse.jetty.ee9:jetty-ee9-security (>= 12.0.0, <= 12.0.35) org.eclipse.jetty:jetty-security (>= 12.1.0, <= 12.1.9) org.eclipse.jetty.ee8:jetty-ee8-security (>= 12.1.0, <= 12.1.9) org.eclipse.jetty.ee9:jetty-ee9-security (>= 12.1.0, <= 12.1.9)

Security releases

org.eclipse.jetty:jetty-security → 9.4.63 (maven) org.eclipse.jetty:jetty-security → 10.0.31 (maven) org.eclipse.jetty:jetty-security → 11.0.31 (maven) org.eclipse.jetty:jetty-security → 12.0.36 (maven) org.eclipse.jetty.ee8:jetty-ee8-security → 12.0.36 (maven) org.eclipse.jetty.ee9:jetty-ee9-security → 12.0.36 (maven) org.eclipse.jetty:jetty-security → 12.1.10 (maven) org.eclipse.jetty.ee8:jetty-ee8-security → 12.1.10 (maven) org.eclipse.jetty.ee9:jetty-ee9-security → 12.1.10 (maven)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Upgrade the following packages to resolve this vulnerability:

org.eclipse.jetty:jetty-security to 9.4.63 or later; org.eclipse.jetty:jetty-security to 10.0.31 or later; org.eclipse.jetty:jetty-security to 11.0.31 or later; org.eclipse.jetty:jetty-security to 12.0.36 or later; org.eclipse.jetty.ee8:jetty-ee8-security to 12.0.36 or later; org.eclipse.jetty.ee9:jetty-ee9-security to 12.0.36 or later; org.eclipse.jetty:jetty-security to 12.1.10 or later; org.eclipse.jetty.ee8:jetty-ee8-security to 12.1.10 or later; org.eclipse.jetty.ee9:jetty-ee9-security to 12.1.10 or later

Kodem Kai can prioritize this vulnerability in your dependency tree and generate a fix recommendation.

Frequently Asked Questions

  1. What is CVE-2026-10050? CVE-2026-10050 is a high-severity security vulnerability in org.eclipse.jetty:jetty-security (maven), affecting versions >= 9.4.0.v20161208, <= 9.4.58.v20250814. It is fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10.
  2. Which packages are affected by CVE-2026-10050?
    • org.eclipse.jetty:jetty-security (maven) (versions >= 9.4.0.v20161208, <= 9.4.58.v20250814)
    • org.eclipse.jetty.ee8:jetty-ee8-security (maven) (versions >= 12.0.0, <= 12.0.35)
    • org.eclipse.jetty.ee9:jetty-ee9-security (maven) (versions >= 12.0.0, <= 12.0.35)
  3. Is there a fix for CVE-2026-10050? Yes. CVE-2026-10050 is fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10. Upgrade to this version or later.
  4. Is CVE-2026-10050 exploitable, and should I be worried? Whether CVE-2026-10050 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2026-10050 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  6. How do I fix CVE-2026-10050?
    • Upgrade org.eclipse.jetty:jetty-security to 9.4.63 or later
    • Upgrade org.eclipse.jetty:jetty-security to 10.0.31 or later
    • Upgrade org.eclipse.jetty:jetty-security to 11.0.31 or later
    • Upgrade org.eclipse.jetty:jetty-security to 12.0.36 or later
    • Upgrade org.eclipse.jetty.ee8:jetty-ee8-security to 12.0.36 or later
    • Upgrade org.eclipse.jetty.ee9:jetty-ee9-security to 12.0.36 or later
    • Upgrade org.eclipse.jetty:jetty-security to 12.1.10 or later
    • Upgrade org.eclipse.jetty.ee8:jetty-ee8-security to 12.1.10 or later
    • Upgrade org.eclipse.jetty.ee9:jetty-ee9-security to 12.1.10 or later

Stop the waste.
Protect your environment with Kodem.