← Back to search

CVE-2026-10050

9.1 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-08

AI risk analysis

Summary
The flaw allows an attacker to bypass authentication by crafting a password with non-ISO-8859-1 characters, which are silently replaced by '?'.
Exploitability
Exploitation is relatively easy if the attacker knows the password length and can craft a request with a password made of '?' characters.
Blast radius
If exploited, this could lead to unauthorized access to protected resources, especially in systems where sensitive data or administrative functions are accessible via digest authentication.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Jetty 11.0.0 or later, as the fix is included in this version.
auth-bypasswebdigest-authiso-8859-1

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-173, CWE-303

Vendors

eclipse

Products

jetty

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.