#1133373 jetty12: CVE-2026-5795

Package:
src:jetty12
Source:
src:jetty12
Submitter:
Salvatore Bonaccorso
Date:
2026-09-28 19:51:01 UTC
Severity:
normal
Tags:
#1133373#5
Date:
2026-04-12 15:16:15 UTC
From:
To:
Hi,

The following vulnerability was published for jetty.

CVE-2026-5795[0]:
| In Eclipse Jetty, the class JASPIAuthenticator initiates the
| authentication checks, which set two ThreadLocal variable.   Upon
| returning from the initial checks, there are conditions that cause
| an early return from the JASPIAuthenticator code without clearing
| those ThreadLocals.   A subsequent request using the same thread
| inherits the ThreadLocal values, leading to a broken access control
| and privilege escalation.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5795
https://www.cve.org/CVERecord?id=CVE-2026-5795
[1] https://github.com/jetty/jetty.project/security/advisories/GHSA-r7p8-xq5m-436c

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1133373#12
Date:
2026-09-28 19:49:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
jetty12, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1133373@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Bourg <ebourg@apache.org> (supplier of updated jetty12 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 21:38:29 +0200
Source: jetty12
Architecture: source
Version: 12.0.39-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg@apache.org>
Closes: 1133373
Changes:
 jetty12 (12.0.39-1) unstable; urgency=medium
 .
   * New upstream release
     - Fixes CVE-2026-5795 (Closes: #1133373)
     - Refreshed the patches
     - Updated the Maven rules
   * Standards-Version updated to 4.7.4
Checksums-Sha1:
 3350a57b12174cc5187e7f9ae1a1016e5cfa54db 3294 jetty12_12.0.39-1.dsc
 6d1f475f5f4554cae7269d4c0284ede72f801497 16497884 jetty12_12.0.39.orig.tar.xz
 0bfe0be2522897a5594570ff2660ae59a9ae5ac3 34032 jetty12_12.0.39-1.debian.tar.xz
 f198691cc85d075150801ff4a23800b59abb3bf8 22094 jetty12_12.0.39-1_source.buildinfo
Checksums-Sha256:
 d2d84b98f2fae73d28b1b956fca8ae42919fedc295f754b930d70f049d8103ac 3294 jetty12_12.0.39-1.dsc
 4c9961c248b2a35aa3f1123361451630e9d7b00d6421486db8eca0883a2a04e5 16497884 jetty12_12.0.39.orig.tar.xz
 a7604e533a83cf9d6118b5faac1998ec55c0b7c1b8bed5801507b6f45cb29055 34032 jetty12_12.0.39-1.debian.tar.xz
 27eadaa73aee7636b16ef6620a4c62d75a3971a1b024a9dc337048b92eafce1e 22094 jetty12_12.0.39-1_source.buildinfo
Files:
 7dba676009d401bdac7c802bc2495c14 3294 java optional jetty12_12.0.39-1.dsc
 f34af419adce05f1545d2c293d258ef5 16497884 java optional jetty12_12.0.39.orig.tar.xz
 c49634e307068d5ec76fabd98a767117 34032 java optional jetty12_12.0.39-1.debian.tar.xz
 bdce433ad21f4e3e1119b7344fac2c50 22094 java optional jetty12_12.0.39-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmq6wksSHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCskxwP/2cQLctGS3yDR6Kx5dYwm+ydwXvfJpXC
AWpu1fZ6A9B+wjZYXatswYcHip8DeDmFmorkjJVzOIEillBoqtLG0I2Ti1gJ9KAo
mp6zHnwMGCuHoKwRIjWbDEZlWM3oP4tIsrIYloMaWECRB6z2FHWfZe/CVA2fm2rL
KC1zkDZu2RAyOOAsSB2UIaQFXii5ONvT2PtgBag7PSjWIHN8tVW5isuPH/5yP98h
Oa54pPixG2/10/lY51YV6eFgOnR1kT3N107uAV3zIKENvylfpINYNo3nfohNhcOs
EcfE45G7igmFyJOJPL3D7sIMVXv1aMsMnceIHFfUFdr+MruKuvr6vL7K6hhSPGUy
yrgvNmG7ooAu3V7ebTXfDjDXgGvY7whJZu5EoFtFQosmIAA0T1LUAQZnGpbDcckK
tQT9c0mD/QtNRZ39/4qtN0629OC4tQuSHJH0/t2POCsAbSpHVVLbAFqdCC5gNM2D
cWs4kJ3U9863f2XrhzEFbK2qulyJXu64EWZWX7wmzbCet79L1yfnPBqloSISniHw
9i2TfMHByJPkD5vwWo3cVicpr7hRwYc/CUmv0MdrROw/CtrjQJzhc9PkQXOTdAvu
9NkswRSDV7pZW5B0PhiKXrPf2g6ENfSvoFd58AdpJmhMrszW9nLR/72ITEaNCxDi
sGLZgoasjRMX
=dpk2
-----END PGP SIGNATURE-----