CVE-2026-10050
Eclipse Foundation Eclipse Jetty - EE8, Eclipse Jetty - EE9, Eclipse Jetty
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password...
- CVSS
- 8.7
- EPSS
- 0.48% 39.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.04