Risk Scores
CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | Eclipse Jetty | 12.1.0, 12.0.0, 11.0.0 |
Timeline
- Apr 14, 2026 CVE Published
- Apr 14, 2026 PoC Published
- Apr 15, 2026 Security Advisory
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37405 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37404 advisory
- https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf third-party-advisory
- https://gitlab.eclipse.org/security/cve-assignment/-/issues/89 issue