[Git][security-tracker-team/security-tracker][master] Add two new jetty issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 17 13:59:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4bf0ffe8 by Salvatore Bonaccorso at 2026-07-17T14:58:59+02:00
Add two new jetty issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1330,7 +1330,11 @@ CVE-2026-8919 (Permissive Cross-domain Security Policy with Untrusted Domains in
 CVE-2026-8590 (Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules ...)
 	NOT-FOR-US: Spotfire
 CVE-2026-8384 (In Eclipse Jetty, an HTTP URI of this form:      /public;/../admin/sec ...)
-	TODO: check
+	- jetty12 <unfixed>
+	- jetty9 <unfixed>
+	NOTE: https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr
+	NOTE: https://github.com/jetty/jetty.project/pull/14969
+	NOTE: Fixed by: https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084 (jetty-12.0.35)
 CVE-2026-8314 (A security issue exists within Arena\xae Simulation due to a memory co ...)
 	NOT-FOR-US: Rockwell Automation
 CVE-2026-8313 (A security issue exists within Arena\xae Simulation due to a memory co ...)
@@ -1344,7 +1348,9 @@ CVE-2026-7494 (Nexus Repository 3 is vulnerable to Server-Side Request Forgery (
 CVE-2026-6851 (An Improper link resolution before file access ('link following') vuln ...)
 	NOT-FOR-US: Bitdefender
 CVE-2026-6790 (In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no  ...)
-	TODO: check
+	- jetty12 <unfixed>
+	- jetty9 <unfixed>
+	NOTE: https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh
 CVE-2026-62659 (A security flaw was discovered in the NETGEAR WAX333 Access Point that ...)
 	NOT-FOR-US: Netgear
 CVE-2026-62658 (A security flaw was discovered in certain NETGEAR Nighthawk RAX series ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bf0ffe8ecdc7ec29bfe989ed047a2c2fb737953

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bf0ffe8ecdc7ec29bfe989ed047a2c2fb737953
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260717/7c7341fa/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list