DEBIAN-CVE-2026-10050

Source
https://security-tracker.debian.org/tracker/CVE-2026-10050
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-10050
Upstream
Published
2026-08-04T11:22:43Z
Modified
2026-09-01T16:06:15Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: αβ123 converts to ??123. An attacker can send a request with a digest Authorization header crafted with a password made of only ? characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest RFC-7616 supports a charset parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

References

Affected packages

Debian:13 / jetty12

Package

Name
jetty12
Purl
pkg:deb/debian/jetty12?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.17-3
12.0.17-3.1~deb13u1
12.0.17-3.1
12.0.32-1
12.0.32-2
12.0.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json"

Debian:14 / jetty12

Package

Name
jetty12
Purl
pkg:deb/debian/jetty12?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.17-3
12.0.17-3.1~deb13u1
12.0.17-3.1
12.0.32-1
12.0.32-2
12.0.33-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json"

Debian:12 / jetty9

Package

Name
jetty9
Purl
pkg:deb/debian/jetty9?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.4.50-4
9.4.50-4+deb12u1
9.4.50-4+deb12u2
9.4.50-4+deb12u3
9.4.51-1
9.4.51-2
9.4.52-1
9.4.53-1
9.4.54-1
9.4.55-1
9.4.56-1
9.4.57-0+deb12u1
9.4.57-1
9.4.57-1.1~deb12u1
9.4.57-1.1~deb13u1
9.4.57-1.1
9.4.58-1
9.4.58-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json"

Debian:13 / jetty9

Package

Name
jetty9
Purl
pkg:deb/debian/jetty9?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.4.57-1
9.4.57-1.1~deb12u1
9.4.57-1.1~deb13u1
9.4.57-1.1
9.4.58-1
9.4.58-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json"

Debian:14 / jetty9

Package

Name
jetty9
Purl
pkg:deb/debian/jetty9?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

9.*
9.4.57-1
9.4.57-1.1~deb12u1
9.4.57-1.1~deb13u1
9.4.57-1.1
9.4.58-1
9.4.58-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10050.json"