{"id":"GHSA-f4v5-65jj-pcr2","summary":"Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections","details":"### Description\n\n\u003e FINDING — MEDIUM (HTTP/1.1 keep-alive connections with trailers)\n\u003e HttpConnection._trailers Cross-Request Leakage (Never Reset Between Requests)\n\u003e \n\u003e Location:\n\u003e   jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/\n\u003e   HttpConnection.java:107, 1157-1161, 1170\n\u003e \n\u003e Detail:\n\u003e   _trailers (line 107) is a connection-scoped HttpFields.Mutable field.\n\u003e   parsedTrailer() (line 1157) populates it when request N carries HTTP trailers.\n\u003e   messageComplete() (line 1170) checks \"if (_trailers != null)\" — evaluates true\n\u003e   from request N's data — and stamps it onto request N+1.\n\u003e \n\u003e   Grep confirms: ZERO occurrences of \"_trailers = null\" in entire HttpConnection.java.\n\u003e \n\u003e   Scenario:\n\u003e     Request N:   POST /upload (trailers: X-Checksum: abc123)\n\u003e     Request N+1: GET  /data   (no trailers)\n\u003e     app: request.getTrailers() on N+1 → returns {X-Checksum: abc123} ← STALE\n\u003e \n\u003e   Application logic branching on getTrailers() != null produces incorrect behavior.\n\u003e   Not cross-connection (same keep-alive connection only).\n\u003e \n\u003e   More dangerous scenario: TOCTOU — trailer passes check, target swapped before use.\n\n### Workarounds\nDo not rely on HTTP request trailers for security-sensitive logic, or disable persistent connections by closing the connection after each HTTP/1.1 request.","aliases":["CVE-2026-10051"],"modified":"2026-09-10T03:50:51.882727145Z","published":"2026-07-22T22:56:05Z","database_specific":{"nvd_published_at":"2026-07-14T09:16:39Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-22T22:56:05Z"},"references":[{"type":"WEB","url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-f4v5-65jj-pcr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10051"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/pull/15162"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/pull/15163"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/commit/72206b3ea623cf7ed8729b47a83ee628ff10e8eb"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/commit/dc27e8d3ab743fe27935ea2d8c41756eb6c5bae9"},{"type":"PACKAGE","url":"https://github.com/jetty/jetty.project"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.0.36"}]}],"versions":["12.0.0","12.0.1","12.0.10","12.0.11","12.0.12","12.0.13","12.0.14","12.0.15","12.0.16","12.0.17","12.0.18","12.0.19","12.0.2","12.0.20","12.0.21","12.0.22","12.0.23","12.0.24","12.0.25","12.0.26","12.0.27","12.0.28","12.0.29","12.0.3","12.0.30","12.0.31","12.0.32","12.0.33","12.0.34","12.0.35","12.0.4","12.0.5","12.0.6","12.0.7","12.0.8","12.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f4v5-65jj-pcr2/GHSA-f4v5-65jj-pcr2.json","last_known_affected_version_range":"\u003c= 12.0.35"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.1.0"},{"fixed":"12.1.10"}]}],"versions":["12.1.0","12.1.1","12.1.2","12.1.3","12.1.4","12.1.5","12.1.6","12.1.7","12.1.8","12.1.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.1.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f4v5-65jj-pcr2/GHSA-f4v5-65jj-pcr2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}