HIGHCVSS 7.4Vulnerability

CVE-2026-5795

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.

Properties

summary
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
severity
HIGH
epss_score
0.00529
cvss_score
7.4
ghsa_published
2026-04-14T00:06:27Z
source_url
https://github.com/advisories/GHSA-r7p8-xq5m-436c
ghsa_updated
2026-04-14T00:06:30Z
ghsa_id
GHSA-r7p8-xq5m-436c
score
7.4
cve_id
CVE-2026-5795
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-04-08T14:16:32.633
last_modified
2026-08-17T12:18:56.247
epss_percentile
0.42635

Related Entities (18)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (2)

[Weakness]Improper Authentication
[Weakness]Sensitive Information in Resource Not Removed Before Reuse

VULNERABLE_TO (6)

[Software]maven/org.eclipse.jetty:jetty-jaspi
[Software]maven/org.eclipse.jetty.ee10:jetty-ee10-jaspi
[Software]maven/org.eclipse.jetty.ee11:jetty-ee11-jaspi
[Software]maven/org.eclipse.jetty.ee8:jetty-ee8-jaspi
[Software]maven/org.eclipse.jetty.ee9:jetty-ee9-jaspi
[Software]maven/org.eclipse.jetty.ee10:jetty-ee10

AFFECTS (6)

[Software]maven/org.eclipse.jetty.ee10:jetty-ee10-jaspi
[Software]maven/org.eclipse.jetty.ee8:jetty-ee8-jaspi
[Software]maven/org.eclipse.jetty.ee9:jetty-ee9-jaspi
[Software]maven/org.eclipse.jetty:jetty-jaspi
[Software]maven/org.eclipse.jetty.ee11:jetty-ee11-jaspi
[Software]maven/org.eclipse.jetty.ee10:jetty-ee10

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph