CVE-2026-10050
Received Received - Intake

Authentication Bypass in Eclipse Jetty via ISO-8859-1 Password Encoding

Vulnerability report for CVE-2026-10050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Eclipse Foundation

Description

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `Ξ±Ξ²123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
eclipse jetty From 9.4.0 (inc) to 9.4.62 (inc)
eclipse jetty From 10.0.0 (inc) to 10.0.30 (inc)
eclipse jetty From 11.0.0 (inc) to 11.0.30 (inc)
eclipse jetty From 12.0.0 (inc) to 12.1.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-173 The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Eclipse Jetty's Digest authentication uses ISO-8859-1 encoding for passwords, which silently replaces non-Latin characters (like Chinese, Cyrillic, or Greek) with question marks. An attacker can exploit this by sending a crafted Authorization header with only question marks, matching any password of the same length containing non-ISO-8859-1 characters.

Detection Guidance

Check if your Eclipse Jetty version is within the affected range (9.4.0–9.4.62, 10.0.0–10.0.30, 11.0.0–11.0.30, 12.0.0–12.1.9). Use commands like 'java -jar start.jar --version' or check your package manager for Jetty versions.

Impact Analysis

This vulnerability allows attackers to bypass authentication by exploiting character substitution, potentially gaining unauthorized access to systems. Users with non-Latin-1 passwords may also experience denial of service as Jetty's Digest client computes hashes differently from servers expecting UTF-8.

Mitigation Strategies

Upgrade to a patched Jetty version (9.4.63+, 10.0.31+, 11.0.31+, 12.0.36+, or 12.1.10+). If upgrading is not possible, disable Digest authentication or ensure passwords use only ISO-8859-1 characters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart