Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5795

30
FAUCET Score

Eclipse Jetty is vulnerable to a ThreadLocal variable management flaw in its JASPIAuthenticator class. When certain conditions trigger an early return from authentication checks, ThreadLocal variables set during the initial authentication process are not properly cleared. Subsequent requests on the same thread inherit these uncleared ThreadLocal values, enabling attackers to bypass access controls and escalate privileges. The vulnerability presents a HIGH severity risk with a CVSS score of 7.4. It requires network access with high complexity but no user interaction or privileges, making it moderately difficult to exploit. The impact is significant, potentially compromising both the confidentiality and integrity of affected systems. There is no indication of active exploitation in the wild. The EPSS score of 0.0002 reflects minimal current exploitation probability, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. Community attention appears limited, as evidenced by its inactive status on the Hot List, suggesting this issue has received relatively restrained attention from the security community despite its HIGH severity rating.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.4.0, <= 9.4.58CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 10.0.0, <= 10.0.26CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 11.0.0, <= 11.0.26CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 12.0.0, < 12.0.34CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 12.1.0, < 12.1.8CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 15th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee11:jetty-ee11-jaspiFixed in: 12.1.8
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee10:jetty-ee10-jaspiFixed in: 12.1.8
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee9:jetty-ee9-jaspiFixed in: 12.1.8
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee8:jetty-ee8-jaspiFixed in: 12.1.8
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee11:jetty-ee11-jaspiFixed in: 12.0.34
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee10:jetty-ee10-jaspiFixed in: 12.0.34
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee9:jetty-ee9-jaspiFixed in: 12.0.34
mavenpatch availablevia ghsa
Product: org.eclipse.jetty.ee8:jetty-ee8-jaspiFixed in: 12.0.34
mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-jaspiFixed in: 11.0.29
mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-jaspiFixed in: 10.0.29
mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-jaspiFixed in: 9.4.61

Vendor Advisories (1)

mavenGHSA-r7p8-xq5m-436chigh

Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:25089
access.redhat.com / errata/RHSA-2026:28573
access.redhat.com / security/cve/CVE-2026-5795
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-5795.json
github.com / jetty/jetty.project/security/advisories/GHSA-r7p8-xq5m-436chttps:/
Broken Link
gitlab.eclipse.org / security/cve-assignment/-/issues/92
Broken Link