Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10051

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintentionally disclose information by reporting the previously retained trailers, or a combination of previous and current request trailers.

Отчет

Moderate: This information disclosure flaw in Eclipse Jetty allows HTTP/1.1 trailers from a previous request to be retained and subsequently exposed to other requests sharing the same connection. This could lead to unintended disclosure of sensitive information in Red Hat products utilizing Jetty, such as Red Hat AMQ and Enterprise Application Platform, particularly when connection reuse is active and trailers contain confidential data. The confidentiality impact is considered low.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
Red Hat AMQ Broker 7jetty-serverAffected
Red Hat build of Apache Camel for Spring Boot 4jetty-serverAffected
Red Hat build of Apache Camel - HawtIO 4jetty-serverAffected
Red Hat build of Apicurio Registry 3jetty-serverNot affected
Red Hat build of Debezium 3jetty-serverAffected
Red Hat Data Grid 8jetty-serverAffected
Red Hat Enterprise Linux 7maven-site-pluginNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2499928jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections

EPSS

Процентиль: 23%
0.00302
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

CVSS3: 7.5
nvd
около 1 месяца назад

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

CVSS3: 7.5
debian
около 1 месяца назад

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ...

github
28 дней назад

Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections

EPSS

Процентиль: 23%
0.00302
Низкий

5.3 Medium

CVSS3