PT-2026-57983 · Eclipse Foundation · Eclipse Jetty

CVE-2026-10051

·

Published

2026-07-14

·

Updated

2026-08-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty (affected versions not specified)
Description A flaw in the handling of HTTP/1.1 requests allows the server to retain trailers from an initial request and apply them to subsequent requests made over the same connection. If a following request does not contain trailers, it will incorrectly report the trailers from the first request. If a following request does contain trailers, it will report a union of the trailers from both the first and the current request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10051
GHSA-F4V5-65JJ-PCR2

Affected Products

Eclipse Jetty