Back

HIGH

Digest authentication lossy encoding

Published Aug 4, 2026

Description

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.

This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.

If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.

An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.

Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

Affected products

Remediation

Red Hat statement

Important: This flaw allows an authentication bypass in Eclipse Jetty's HTTP Digest authentication. An attacker who knows a victim's username can craft a collision password if the original password contains non-Latin-1 characters, leading to unauthorized access in affected Red Hat products that utilize this authentication method.

Red Hat mitigation

To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass.

Metrics

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner eclipse
Published Aug 4, 2026
Updated Aug 4, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Aug 4, 2026
NVD
Status Analyzed
Modified Aug 8, 2026
Red Hat
Severity Important
Public date Jul 16, 2026
GHSA-2FVJ-HGJ9-J2GR