HIGHCVSS 7.4Vulnerability
CVE-2026-5795
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.
Properties
- summary
- Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
- severity
- HIGH
- epss_score
- 0.00529
- cvss_score
- 7.4
- ghsa_published
- 2026-04-14T00:06:27Z
- source_url
- https://github.com/advisories/GHSA-r7p8-xq5m-436c
- ghsa_updated
- 2026-04-14T00:06:30Z
- ghsa_id
- GHSA-r7p8-xq5m-436c
- score
- 7.4
- cve_id
- CVE-2026-5795
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- published_at
- 2026-04-08T14:16:32.633
- last_modified
- 2026-08-17T12:18:56.247
- epss_percentile
- 0.42635
Related Entities (18)
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (2)
→[Weakness]Improper Authentication
→[Weakness]Sensitive Information in Resource Not Removed Before Reuse
VULNERABLE_TO (6)
←[Software]maven/org.eclipse.jetty:jetty-jaspi
←[Software]maven/org.eclipse.jetty.ee10:jetty-ee10-jaspi
←[Software]maven/org.eclipse.jetty.ee11:jetty-ee11-jaspi
←[Software]maven/org.eclipse.jetty.ee8:jetty-ee8-jaspi
←[Software]maven/org.eclipse.jetty.ee9:jetty-ee9-jaspi
←[Software]maven/org.eclipse.jetty.ee10:jetty-ee10
AFFECTS (6)
→[Software]maven/org.eclipse.jetty.ee10:jetty-ee10-jaspi
→[Software]maven/org.eclipse.jetty.ee8:jetty-ee8-jaspi
→[Software]maven/org.eclipse.jetty.ee9:jetty-ee9-jaspi
→[Software]maven/org.eclipse.jetty:jetty-jaspi
→[Software]maven/org.eclipse.jetty.ee11:jetty-ee11-jaspi
→[Software]maven/org.eclipse.jetty.ee10:jetty-ee10
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph