Skip to content

[fix][sec] Upgrade Jetty to address CVE-2026-2332 - #25527

Merged
lhotari merged 1 commit into
apache:masterfrom
lhotari:lh-upgrade-jetty-12.1.7
Apr 15, 2026
Merged

[fix][sec] Upgrade Jetty to address CVE-2026-2332#25527
lhotari merged 1 commit into
apache:masterfrom
lhotari:lh-upgrade-jetty-12.1.7

Conversation

@lhotari

@lhotari lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member

Motivation

There's a new CVE in Jetty, CVE-2026-2332. The fix is in 12.1.7 / 9.4.60 (will be used when backporting to maintenance branches).

Modifications

  • Upgrade Jetty to 12.1.7

@lhotari
lhotari merged commit 4c96c73 into apache:master Apr 15, 2026
80 of 83 checks passed
lhotari added a commit that referenced this pull request Apr 15, 2026
@lhotari

lhotari commented Apr 15, 2026

Copy link
Copy Markdown
Member Author

For Jetty 9.4.x, the fix is only available for paying customers.
Commercial services: https://webtide.com/end-of-life/
Links to partners such as herodevs, their page: https://www.herodevs.com/blog-posts/cve-2026-5795-jetty-authentication-bypass-and-privilege-escalation-jaspiauthenticator.
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants