StackRadar

CVE-2026-10050

High

Advisory

Published 22 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
243
deployed by those charts
Fix available
3 of 3
affected packages

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 243 images.

Affected packageAffected versionsFixed inImages
jetty-securitymaven9.4.5.v20170502, 9.4.6.v20170531, 9.4.8.v20171121, 9.4.10.v20180503+71 more9.4.63, 10.0.31, 11.0.31, 12.0.36+1 more243
jetty-ee8-securitymaven12.0.25, 12.1.6, 12.1.812.0.36, 12.1.1010
jetty-ee9-securitymaven12.1.3, 12.1.5, 12.1.6, 12.1.7+1 more12.1.109
OSV records
GHSA-2fvj-hgj9-j2gr

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
jetty-security@9.4.49.v20220914
9.4.63

Open the chart page →

13,767
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-security@9.4.48.v20220622
9.4.63

Open the chart page →

18,756
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
jetty-security@9.4.51.v20230217
9.4.63

Open the chart page →

4,240
clickhousetemp-charts0.7.11 of 3See more

clickhouse temp-charts 0.7.1

1 of the 3 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
library/zookeeper:3.6.180ad2170ad62
jetty-security@9.4.24.v20191120
9.4.63

Open the chart page →

8,707
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jetty-security@11.0.26
11.0.31

Open the chart page →

1,825
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jetty-security@12.0.34
12.0.36

Open the chart page →

1,551
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jetty-security@9.4.57.v20241219
9.4.63

Open the chart page →

1,733
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jetty-security@9.4.54.v20240208
9.4.63

Open the chart page →

45,239
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-security@9.4.12.v20180830
9.4.63

Open the chart page →

4,649
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-security@9.4.44.v20210927
9.4.63
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
jetty-security@9.4.51.v20230217
9.4.63

Open the chart page →

9,397
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
jetty-security@12.0.12
12.0.36

Open the chart page →

2,634
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-10050.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jetty-ee9-security@12.1.7
jetty-security@12.1.7
12.1.10
12.1.10

Open the chart page →

1,639

Container images carrying it

243 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
sonatype/nexus3:3.58.1586060431b64
jetty-security@9.4.51.v20230217
9.4.63
1
stain/jena-fuseki:latestb1d0c96f19ad
jetty-security@12.0.11
12.0.36
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-security@9.4.48.v20220622
9.4.63
1
tchiotludo/akhq:0.28.0c2824dc2ae44
jetty-security@12.1.8
12.1.10
1
thehiveproject/cortex:3.1.7f4bc64fb8844
jetty-security@9.4.39.v20210325
9.4.63
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-security@9.4.6.v20170531
9.4.63
1
traccar/traccar:6.7-alpine621c8d6d46fd
jetty-security@11.0.25
11.0.31
1
trinodb/trino:4801565e8cac299
jetty-security@12.1.7
12.1.10
1
trinodb/trino:45038c6f24ab1a4
jetty-security@9.4.50.v20221201
9.4.63
1
trinodb/trino:4815b5e0a97f599
jetty-security@12.1.9
12.1.10
1
trinodb/trino:4796af989b0846d
jetty-security@12.1.5
12.1.10
1
trinodb/trino:405ee80ab5eeab2
jetty-security@9.4.49.v20220914
9.4.63
1
verapdf/rest:v1.30.2341359ac6af5
jetty-security@10.0.26
10.0.31
1
voltha/voltha-onos:5.1.8e038acb950d3
jetty-security@9.4.43.v20210629
9.4.63
1
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-security@9.4.27.v20200227
9.4.63
1
wistefan/mvf:lateste0887302b2d8
jetty-security@9.4.48.v20220622
9.4.63
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jetty-security@9.4.48.v20220622
9.4.63
1
ghcr.io/comet-ml/opik/opik-backend:2.2.5950a7aa0562f5
jetty-security@12.1.9
12.1.10
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
jetty-security@12.0.25
12.0.36
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-security@9.4.56.v20240826
9.4.63
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-security@9.4.46.v20220331
9.4.63
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-security@9.4.43.v20210629
9.4.63
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-security@9.4.30.v20200611
9.4.63
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jetty-security@11.0.26
11.0.31
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-security@9.4.56.v20240826
9.4.63
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jetty-security@9.4.56.v20240826
9.4.63
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
jetty-security@9.4.56.v20240826
9.4.63
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-security@9.4.43.v20210629
9.4.63
1
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
jetty-security@12.0.34
12.0.36
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-security@9.4.53.v20231009
9.4.63
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-security@9.4.43.v20210629
9.4.63
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jetty-security@12.1.8
12.1.10
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jetty-security@12.1.8
12.1.10
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
jetty-security@9.4.53.v20231009
9.4.63
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
jetty-security@9.4.53.v20231009
9.4.63
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
jetty-security@10.0.20
10.0.31
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-security@9.4.12.v20180830
9.4.63
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-security@9.4.58.v20250814
9.4.63
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jetty-security@12.0.25
12.0.36
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-security@9.4.51.v20230217
9.4.63
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jetty-security@12.0.16
12.0.36
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-security@9.4.48.v20220622
9.4.63
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-security@9.4.11.v20180605
9.4.63
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.