Digest authentication lossy encoding
Published Aug 4, 2026
8.7
HIGHCVSS 4.0
EPSS 0.63%
Description
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.
This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.
If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.
An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.
Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.
Affected products
-
- Version 10.0.0StatusaffectedConstraints<=10.0.30
- Version 11.0.0StatusaffectedConstraints<=11.0.30
- Version 12.0.0StatusaffectedConstraints<=12.0.35
- Version 12.1.0StatusaffectedConstraints<=12.1.9
- Version 9.4.0StatusaffectedConstraints<=9.4.62
- Version
-
- Version 12.0.0StatusaffectedConstraints<=12.0.35
- Version 12.1.0StatusaffectedConstraints<=12.1.9
- Version
-
- Version 12.0.0StatusaffectedConstraints<=12.0.35
- Version 12.1.0StatusaffectedConstraints<=12.1.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Eclipse Foundation | Eclipse Jetty | unaffected |
| ||||||||||||||||||
| Eclipse Foundation | Eclipse Jetty - EE8 | unaffected |
| ||||||||||||||||||
| Eclipse Foundation | Eclipse Jetty - EE9 | unaffected |
|
No data.
Red Hat AMQ Broker 7.13.6
jetty-security
Fixed · RHSA-2026:66545
Red Hat AMQ Broker 7.14.1
jetty-security
Fixed · RHSA-2026:66488
Red Hat OpenShift Dev Spaces 3.30
devspaces/openvsx-rhel9:1787759145
Fixed · RHSA-2026:62260
Red Hat OpenShift Dev Spaces 3.30
devspaces/pluginregistry-rhel9:1787759723
Fixed · RHSA-2026:62260
OpenShift Developer Tools and Services
jenkins
Affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Affected
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Affected
Red Hat Data Grid 8
jetty-security
Not affected
Red Hat Enterprise Linux 7
maven-wagon
Not affected
Red Hat Enterprise Linux 9
jmc
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-security
Not affected
Red Hat Offline Knowledge Portal
offline-knowledge-portal/rhokp-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-spark-operator-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Not affected
Red Hat Satellite 6
openvox-server
Not affected
Red Hat Satellite 6
puppetserver
Not affected
Red Hat Satellite 6
satellite:el8/puppetserver
Affected
Red Hat Single Sign-On 7
jetty-security
Affected
Red Hat build of Apache Camel - HawtIO 4
jetty-security
Affected
Red Hat build of Apache Camel for Spring Boot 4
jetty-security
Affected
Red Hat build of Apicurio Registry 3
jetty-security
Not affected
Red Hat build of Debezium 3
jetty-security
Affected
streams for Apache Kafka 2
jetty-security
Affected
streams for Apache Kafka 3
jetty-security
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7.13.6 | jetty-security | Fixed | RHSA-2026:66545 |
| Red Hat AMQ Broker 7.14.1 | jetty-security | Fixed | RHSA-2026:66488 |
| Red Hat OpenShift Dev Spaces 3.30 | devspaces/openvsx-rhel9:1787759145 | Fixed | RHSA-2026:62260 |
| Red Hat OpenShift Dev Spaces 3.30 | devspaces/pluginregistry-rhel9:1787759723 | Fixed | RHSA-2026:62260 |
| OpenShift Developer Tools and Services | jenkins | Affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | n/a |
| Red Hat Data Grid 8 | jetty-security | Not affected | n/a |
| Red Hat Enterprise Linux 7 | maven-wagon | Not affected | n/a |
| Red Hat Enterprise Linux 9 | jmc | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-security | Not affected | n/a |
| Red Hat Offline Knowledge Portal | offline-knowledge-portal/rhokp-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat Satellite 6 | openvox-server | Not affected | n/a |
| Red Hat Satellite 6 | puppetserver | Not affected | n/a |
| Red Hat Satellite 6 | satellite:el8/puppetserver | Affected | n/a |
| Red Hat Single Sign-On 7 | jetty-security | Affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | jetty-security | Affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | jetty-security | Affected | n/a |
| Red Hat build of Apicurio Registry 3 | jetty-security | Not affected | n/a |
| Red Hat build of Debezium 3 | jetty-security | Affected | n/a |
| streams for Apache Kafka 2 | jetty-security | Affected | n/a |
| streams for Apache Kafka 3 | jetty-security | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Important: This flaw allows an authentication bypass in Eclipse Jetty's HTTP Digest authentication. An attacker who knows a victim's username can craft a collision password if the original password contains non-Latin-1 characters, leading to unauthorized access in affected Red Hat products that utilize this authentication method.
Red Hat mitigation
To mitigate this vulnerability, ensure that all user passwords configured for HTTP Digest authentication in affected Eclipse Jetty deployments exclusively use characters within the Latin-1 character set. This prevents the character encoding collision that leads to authentication bypass.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Aug 4, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.63% (0.00632) | 48.40th | v5 (v2026.06.15) |
| Aug 5, 2026 | 0.41% (0.00413) | 33.95th | v5 (v2026.06.15) |
References (14)
- https://access.redhat.com/security/cve/CVE-2026-10050 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510732 Issue Tracking
- https://github.com/advisories/GHSA-2fvj-hgj9-j2gr Advisory
- https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d
- https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d
- https://github.com/jetty/jetty.project/issues/15136
- https://github.com/jetty/jetty.project/pull/15160
- https://github.com/jetty/jetty.project/pull/15183
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10
- https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr exploitVendor Advisory
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-10050
- https://www.cve.org/CVERecord?id=CVE-2026-10050
Change history (0)
No recorded changes yet.