Threat Advisory

Eclipse Jetty Vulnerability Evades Access Controls

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, identified as CVE-2026-8384 with a CVSS score of 5.3, affects Eclipse Jetty’s rating block custom icon rendering component. This flaw allows an unauthenticated attacker to bypass configured path-based security constraints through the environment template management API, potentially leading to business disruption and unauthorized data exposure. The issue occurs due to improper URI path normalization, where URIUtil.canonicalPath fails to correctly process dot-dot (..) path segments when a semicolon path parameter marker is followed by a slash and a dot segment. This can result in an incorrectly normalized canonical path that does not match protected resource prefixes, enabling security constraint bypass. An example exploitation request may include a semicolon path parameter followed by a slash and dot segment, such as /public;/... The affected package is org.eclipse.jetty:jetty-util.

RECOMMENDATIONS:

  • We strongly recommend you update org.eclipse.jetty:jetty-util to below version:
  • CVE-2026-8384: https://github.com/advisories/GHSA-w7x5-g22v-xqhr

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, identified as CVE-2026-8384 with a CVSS score of 5.3, affects Eclipse Jetty’s rating block custom icon rendering component. This flaw allows an unauthenticated attacker to bypass configured path-based security constraints through the environment template management API, potentially leading to business disruption and unauthorized data exposure. The issue occurs due to improper URI path normalization, where URIUtil.canonicalPath fails to correctly process dot-dot (..) path segments when a semicolon path parameter marker is followed by a slash and a dot segment. This can result in an incorrectly normalized canonical path that does not match protected resource prefixes, enabling security constraint bypass. An example exploitation request may include a semicolon path parameter followed by a slash and dot segment, such as /public;/... The affected package is org.eclipse.jetty:jetty-util.

RECOMMENDATIONS:

  • We strongly recommend you update org.eclipse.jetty:jetty-util to below version:
  • CVE-2026-8384: https://github.com/advisories/GHSA-w7x5-g22v-xqhr

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu