Back

MEDIUM

jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications

Published Jul 14, 2026

Description

In Eclipse Jetty, an HTTP URI of this form:

/public;/../admin/secret.txt

results in an unresolved path of:

/public/../admin/secret.txt

instead of the expected:

/admin/secret.txt

Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).

However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.

Affected products

Remediation

Red Hat statement

Moderate impact: This path confusion vulnerability in Eclipse Jetty affects web applications that rely on Jetty to provide resolved paths. While Jetty itself correctly handles these paths and prevents direct file serving, vulnerable web applications may misinterpret unresolved paths, potentially leading to information disclosure.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner eclipse
Published Jul 14, 2026
Updated Jul 14, 2026
Reserved May 12, 2026
CISA Vulnrichment
Updated Jul 14, 2026
NVD
Status Analyzed
Modified Jul 14, 2026
Red Hat
Severity Moderate
Public date Jul 14, 2026
GHSA-W7X5-G22V-XQHR