| Bug | trixie | forky | sid | Description |
|---|
| CVE-2026-8384 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/sec ... |
| CVE-2026-6790 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no ... |
| CVE-2026-5795 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentic ... |
| CVE-2026-2332 | vulnerable | fixed | fixed | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggli ... |
| CVE-2026-1605 | vulnerable | fixed | fixed | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class Gzi ... |
| CVE-2025-11143 | vulnerable (no DSA) | fixed | fixed | The Jetty URI parser has some key differences to other common parsers ... |