jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
Published Jul 14, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.33%
Description
In Eclipse Jetty, an HTTP URI of this form:
/public;/../admin/secret.txt
results in an unresolved path of:
/public/../admin/secret.txt
instead of the expected:
/admin/secret.txt
Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).
However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.
Affected products
-
- Version 12.0.0StatusaffectedConstraints<=12.0.34
- Version 12.1.0StatusaffectedConstraints<=12.1.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Eclipse Foundation | Eclipse Jetty | unaffected |
|
No data.
OpenShift Developer Tools and Services
jenkins
Fix deferred
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Fix deferred
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Fix deferred
Red Hat AMQ Broker 7
jetty-util
Fix deferred
Red Hat Data Grid 8
jetty-util
Fix deferred
Red Hat Enterprise Linux 6
jetty-eclipse
Fix deferred
Red Hat Enterprise Linux 7
maven-site-plugin
Fix deferred
Red Hat Enterprise Linux 9
jmc
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-util
Fix deferred
Red Hat Offline Knowledge Portal
offline-knowledge-portal/rhokp-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-spark-operator-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Fix deferred
Red Hat Satellite 6
openvox-server
Fix deferred
Red Hat Satellite 6
puppetserver
Fix deferred
Red Hat Satellite 6
satellite-capsule:el8/puppetserver
Fix deferred
Red Hat Single Sign-On 7
jetty-util
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
jetty-util
Fix deferred
Red Hat build of Apache Camel 4 for Quarkus 3
jetty-util
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
jetty-util
Fix deferred
Red Hat build of Apicurio Registry 3
jetty-util
Fix deferred
Red Hat build of Debezium 3
jetty-util
Fix deferred
streams for Apache Kafka 2
jetty-util
Fix deferred
streams for Apache Kafka 3
jetty-util
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | n/a |
| Red Hat AMQ Broker 7 | jetty-util | Fix deferred | n/a |
| Red Hat Data Grid 8 | jetty-util | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | jetty-eclipse | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | maven-site-plugin | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | jmc | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-util | Fix deferred | n/a |
| Red Hat Offline Knowledge Portal | offline-knowledge-portal/rhokp-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred | n/a |
| Red Hat Satellite 6 | openvox-server | Fix deferred | n/a |
| Red Hat Satellite 6 | puppetserver | Fix deferred | n/a |
| Red Hat Satellite 6 | satellite-capsule:el8/puppetserver | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | jetty-util | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | jetty-util | Fix deferred | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | jetty-util | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | jetty-util | Fix deferred | n/a |
| Red Hat build of Apicurio Registry 3 | jetty-util | Fix deferred | n/a |
| Red Hat build of Debezium 3 | jetty-util | Fix deferred | n/a |
| streams for Apache Kafka 2 | jetty-util | Fix deferred | n/a |
| streams for Apache Kafka 3 | jetty-util | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate impact: This path confusion vulnerability in Eclipse Jetty affects web applications that rely on Jetty to provide resolved paths. While Jetty itself correctly handles these paths and prevents direct file serving, vulnerable web applications may misinterpret unresolved paths, potentially leading to information disclosure.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.33% (0.00330) | 23.77th | v5 (v2026.06.15) |
| Jul 14, 2026 | 0.19% (0.00191) | 8.95th | v5 (v2026.06.15) |
References (13)
- https://access.redhat.com/security/cve/CVE-2026-8384 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2499932 Issue Tracking
- https://github.com/advisories/GHSA-w7x5-g22v-xqhr Advisory
- https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084
- https://github.com/jetty/jetty.project/commit/ade27ce93a37c33278720250d85c48601230ae3f
- https://github.com/jetty/jetty.project/pull/14969
- https://github.com/jetty/jetty.project/pull/14973
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9
- https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108 Vendor AdvisoryExploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-8384
- https://www.cve.org/CVERecord?id=CVE-2026-8384
Change history (0)
No recorded changes yet.