CVE-2026-10051

Aliases:DEBIAN-CVE-2026-10051GHSA-f4v5-65jj-pcr2CGA-23cv-4qqh-985cCGA-2mwx-w9q8-3j2jCGA-2pp8-27v3-c3j9CGA-35f5-4472-6233CGA-3rr7-4cm7-r3j5CGA-47p9-h5qf-wjhrCGA-4jpw-5rjh-4hv5CGA-4wfp-f489-3qrwCGA-5qgq-5wjr-q4vmCGA-5wg5-vfm3-3mxjCGA-6pr6-xcrx-fgj5CGA-6w6q-644c-ppw2CGA-765r-7x86-j6gjCGA-78ww-pwvr-4xwcCGA-7h55-2hq7-m32rCGA-82xq-xqj6-p52xCGA-88x8-mvgm-7x6jCGA-8vr9-85q4-wvf3CGA-c6jr-q9pq-38v7CGA-c7m5-gh92-p8c2CGA-f6j6-p6cx-hh57CGA-fh67-xh59-3rc9CGA-h42j-7rq7-j254CGA-h67p-pqrq-22wwCGA-hpm6-mg6g-j748CGA-j77r-6rf4-9567CGA-p735-wcx6-p8qjCGA-pmp6-hx82-4mrpCGA-pwg3-qh8c-ch45CGA-2522-7gx6-qhhgCGA-29qp-m68h-wrxqCGA-2r52-c552-pg42CGA-346v-vmgx-wq3fCGA-3g8r-c34j-rjm6CGA-4673-4cv8-v75rCGA-475p-jf5f-7g59CGA-49r9-74pp-f8mfCGA-4h7v-7mjh-pmxjCGA-52fc-pf97-c93qCGA-6f67-8xfw-jv4rCGA-6j6f-mv84-j7vqCGA-6r79-27v2-q8wjCGA-6vfp-2x8g-85vgCGA-7gh6-678f-95m7CGA-7hv9-vcgq-g73cCGA-85wv-mhvq-gmrrCGA-8fhq-xwg5-xxvvCGA-8rjv-g24m-cmv6CGA-9339-3q7c-mwq8CGA-93cp-2jf3-cpjpCGA-9849-v23j-9fjhCGA-9pfm-g9v9-hghwCGA-f5vj-5f2q-r98jCGA-f6h9-3vpf-7fm7CGA-fc54-wh7v-xr77CGA-fc9q-37cj-h2wcCGA-fmvg-cqgp-gcwvCGA-fv8j-rh8p-q4j7CGA-g8wp-998x-2p9rCGA-ggvh-vmgg-vvprCGA-gxmx-gc4r-c2q4CGA-h5g2-5m7w-h4g9CGA-h8r2-p2fc-3j4wCGA-j26c-4mrf-48gwCGA-j2fq-pr87-jx2cCGA-j36x-9cq7-62rxCGA-j3mf-5jq6-mqm7CGA-j686-3fjv-jxgvCGA-jh2f-72gf-9p7gCGA-jj3v-33vc-6p8gCGA-jx56-6gw9-g8mwCGA-m674-323c-553pCGA-m78m-ppjf-pj25CGA-mgwv-mr5g-xg25CGA-mphh-2wh6-cwx9CGA-mvxg-85c5-4ccqCGA-mwf2-cgpr-q956CGA-mxrc-5m2g-xqg6CGA-pvgm-284q-w4xjCGA-q3cq-9w25-x9h4CGA-qc83-w455-w88cCGA-qg25-cr55-gcx7CGA-qj53-pr4w-jp3qCGA-r245-r953-w2chCGA-r2fq-3h4m-qwm5CGA-r3mf-52jw-vqf3CGA-r9cg-mvh8-vq9gCGA-rc46-778m-xpggCGA-rpf6-wv23-5jppCGA-v747-9c2p-35x9CGA-v84p-rf5h-7rvhCGA-v9rq-v7fh-fp4rCGA-vpvc-vc3g-vjv2CGA-vrhp-hvmx-fr3mCGA-wh82-m34j-qgg4CGA-wv7c-f243-4r9jCGA-wxfw-rh6m-3ggxCGA-wxvr-8vx5-mgv6CGA-x24j-46jp-267rCGA-x424-gwcw-3cp8CGA-x4h5-wx59-56f4CGA-x9w7-f96h-x2qjCGA-xpjq-8v88-f2vfCGA-xxv7-qm4q-cpv5CGA-5g6f-5jcx-qvcrCGA-68m2-2rx5-q65jCGA-7r4x-h439-h4cqCGA-8xmg-5f2h-v4xvCGA-97mc-2pg2-vj7fCGA-f7xq-g6qh-xj46CGA-r2v7-fmf3-fjm4CGA-5vjc-69ww-7m59CGA-w995-j66g-pqhvCGA-2chm-472m-cp9jCGA-534p-r9gh-mf9gCGA-5qh5-3xrv-g2w9CGA-6q98-f49p-h667CGA-75w5-3c87-53p2CGA-7wjc-6m3q-3g2gCGA-c5hg-cmjh-rrqgCGA-fjj3-c7r4-5cc7CGA-fx2w-f952-8cxxCGA-m89v-54xg-mxj4CGA-mf42-8h62-w4w7CGA-mpgf-6cxm-q4c5CGA-mw67-p394-jq64CGA-pc2h-jv2v-c629CGA-qmrw-fqvx-jp2rCGA-75j2-xv2w-r348CGA-8hvf-6jf2-xr39
Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 14 Jul 2026, 08:44
Last modified:14 Jul 2026, 12:57

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.3% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

14 Jul 2026, 08:44
Published
Vulnerability first disclosed
14 Jul 2026, 12:57
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

CVSS Metrics

  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.30% Percentile: 23%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • chainguardakhq

    < 0.27.1-r16

  • chainguardapache-hop

    < 2.18.1-r16

  • chainguardapache-hop-fips

    < 2.18.1-r8

  • chainguardapache-jena-fuseki

    < 6.2.0-r2

  • chainguardconfluent-kafka

    < 8.4.0.397-r0

  • chainguardconfluent-kafka-jre-bcfips

    < 8.4.0.382-r0

  • chainguarddependency-track

    < 4.14.3-r0

  • chainguarddependency-track-bundled

    < 4.14.3-r0

  • chainguarddruid

    < 37.0.0-r47 | < 37.0.0-r56

  • chainguardjenkins-2.541

    all

  • chainguardjenkins-2.541-openjdk-17

    all

  • chainguardjenkins-2.541-openjdk-21

    all

  • chainguardjenkins-2.541-openjdk-25

    all

  • chainguardjenkins-2.555

    all

  • chainguardjenkins-2.555-openjdk-21

    all

  • chainguardjenkins-2.555-openjdk-25

    all

  • chainguardjenkins-2.568

    < 2.568.1-r1

  • chainguardjenkins-2.568-openjdk-21

    < 2.568.1-r1

  • chainguardjenkins-2.568-openjdk-25

    < 2.568.1-r1

  • chainguardkafka_exporter-strimzi-compat

    < 1.2.0-r4 | all | < 1.2.0-r5

  • chainguardkafka-4.0

    < 4.0.2-r7

  • chainguardkafka-fips-4.3

    < 4.3.1-r3

  • chainguardkafka-strimzi-compat

    all | < 1.2.0-r5

  • chainguardneo4j-2025.12

    all

  • chainguardneo4j-2026.01

    all

  • chainguardneo4j-2026.02

    all

  • chainguardneo4j-2026.03

    < 2026.03.1-r1

  • chainguardneo4j-2026.04

    all

  • chainguardneo4j-2026.05

    all

  • chainguardneo4j-2026.06

    < 2026.06.0-r3

  • chainguardneo4j-5.26

    < 5.26.28-r5

  • chainguardprometheus-jmx-exporter-strimzi-compat

    < 1.6.0-r0

  • chainguardreposilite

    < 3.6.2-r2

  • chainguardsolr-10

    < 10.0.0-r8

  • chainguardsolr-10-iamguarded-compat

    < 10.0.0-r8

  • chainguardsolr-fips-10

    < 10.0.0-r2

  • chainguardsolr-fips-10-iamguarded-compat

    < 10.0.0-r2

  • chainguardspark-4.2-scala-2.13

    < 4.2.0-r1

  • chainguardspark-fips-4.2-scala-2.13

    < 4.2.0-r1

  • chainguardspark-kubernetes-operator

    < 1.0.0-r0

  • chainguardspark-kubernetes-operator-fips

    < 1.0.0-r0

  • chainguardstrimzi-kafka-operator

    all | < 1.2.0-r5

  • chainguardstrimzi-kafka-operator-cluster-operator

    all | < 1.2.0-r4 | < 1.1.0-r4 | < 1.2.0-r5

  • chainguardstrimzi-kafka-operator-fips-cluster-operator

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-fips-kafka-agent

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-fips-kafka-init

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-fips-topic-operator

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-fips-tracing-agent

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-fips-user-operator

    < 1.1.0-r1

  • chainguardstrimzi-kafka-operator-kafka-agent

    < 1.1.0-r4 | all | < 1.2.0-r5

Showing first 50 affected entries in server-rendered view.

References (12)