CVE-2026-8384

EUVD-2026-43647
In Eclipse Jetty, an HTTP URI of this form:





/public;/../admin/secret.txt








results in an unresolved path of:





/public/../admin/secret.txt








instead of the expected:





/admin/secret.txt








Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).




However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.37%
Affected Products (NVD)
VendorProductVersion
eclipsejetty
12.0.0 ≤
𝑥
< 12.0.35
eclipsejetty
12.1.0 ≤
𝑥
< 12.1.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty12
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
jetty9
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty12
jammy
dne
noble
dne
resolute
needs-triage
jetty9
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage