A medium-severity vulnerability, identified as CVE-2026-8384 with a CVSS score of 5.3, affects Eclipse Jetty’s rating block custom icon rendering component. This flaw allows an unauthenticated attacker to bypass configured path-based security constraints through the environment template management API, potentially leading to business disruption and unauthorized data exposure. The issue occurs due to improper URI path normalization, where URIUtil.canonicalPath fails to correctly process dot-dot (..) path segments when a semicolon path parameter marker is followed by a slash and a dot segment. This can result in an incorrectly normalized canonical path that does not match protected resource prefixes, enabling security constraint bypass. An example exploitation request may include a semicolon path parameter followed by a slash and dot segment, such as /public;/... The affected package is org.eclipse.jetty:jetty-util.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A medium-severity vulnerability, identified as CVE-2026-8384 with a CVSS score of 5.3, affects Eclipse Jetty’s rating block custom icon rendering component. This flaw allows an unauthenticated attacker to bypass configured path-based security constraints through the environment template management API, potentially leading to business disruption and unauthorized data exposure. The issue occurs due to improper URI path normalization, where URIUtil.canonicalPath fails to correctly process dot-dot (..) path segments when a semicolon path parameter marker is followed by a slash and a dot segment. This can result in an incorrectly normalized canonical path that does not match protected resource prefixes, enabling security constraint bypass. An example exploitation request may include a semicolon path parameter followed by a slash and dot segment, such as /public;/... The affected package is org.eclipse.jetty:jetty-util.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]