🔐 CVE Alert

CVE-2026-10050

UNKNOWN 0.0

Digest authentication lossy encoding

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

CWE CWE-173 CWE-303
Vendor eclipse foundation
Product eclipse jetty - ee8
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse jetty - ee8

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse jetty - ee8 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Jetty - EE8
12.0.0 ≤ 12.0.35 12.1.0 ≤ 12.1.9
Eclipse Foundation / Eclipse Jetty - EE9
12.0.0 ≤ 12.0.35 12.1.0 ≤ 12.1.9
Eclipse Foundation / Eclipse Jetty
9.4.0 ≤ 9.4.62 10.0.0 ≤ 10.0.30 11.0.0 ≤ 11.0.30 12.0.0 ≤ 12.0.35 12.1.0 ≤ 12.1.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120

Credits

https://github.com/hrykx-zy