| Bug | trixie | forky | sid | Description |
|---|
| CVE-2026-10051 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... |
| CVE-2026-10050 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, the Digest authentication server-side component uses ... |
| CVE-2026-8384 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/sec ... |
| CVE-2026-6790 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no ... |
| CVE-2026-5795 | vulnerable | vulnerable | vulnerable | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentic ... |
| CVE-2026-2332 | vulnerable | fixed | fixed | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggli ... |
| CVE-2026-1605 | vulnerable | fixed | fixed | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class Gzi ... |
| CVE-2025-11143 | vulnerable (no DSA) | fixed | fixed | The Jetty URI parser has some key differences to other common parsers ... |
| CVE-2024-7708 | undetermined | undetermined | undetermined | For requests that have a body, but reading the body may end up in read ... |