{"id":"GHSA-7p3p-8qv8-m2vh","summary":"Eclipse Jetty: HTTP Authority/Host mismatch","details":"#### Summary\n\nJetty currently accepts HTTP/2 and HTTP/3 requests where the regular\nHost header and the pseudo-header :authority\ndo not match. As a result, the same request can carry two different host identities\nthrough Jetty:\n\n- logic based on `HttpURI` / `Request.getServerName(request)` uses `:authority`\n- logic based on raw request headers continues to use `Host`\n\nThis creates a host/authority confusion condition that can break\nsecurity assumptions in higher layers.\n\nJetty already performs an explicit authority/Host consistency check on\nthe HTTP/1.1 path, but equivalent validation is missing on the HTTP/2\nand HTTP/3 paths.\n\n#### Security Impact\n\nThis issue is not inherently remote code execution, but it can become\nsecurity-relevant in deployments that rely on the request host for\nsecurity-sensitive decisions, including:\n\n- host-based access control\n- virtual host isolation\n- multi-tenant routing by hostname\n- login/logout/callback URL construction\n- reverse proxy and forwarded-header trust chains\n- auditing, cache keys, and absolute URL generation\n\nPotential consequences include:\n\n- bypass of host-based ACLs\n- virtual host or tenant isolation failures\n- incorrect or attacker-influenced redirect/callback targets\n- inconsistent proxy/downstream interpretation of the original target host\n- misleading logs and audit records\n\n#### Technical Root Cause\n\n1. On the HTTP/2 and HTTP/3 metadata builder paths:\n\n- `:authority` is parsed separately into authority/URI state\n- `Host` is preserved as a normal request header\n- the two values are not compared for consistency\n\n2. On the HTTP/2 and HTTP/3 server entry paths:\n\n- Jetty calls `ComplianceUtils.verify(httpCompliance, requestMetaData, listener)`\n- this verification does not enforce `MISMATCHED_AUTHORITY`\n\n3. On the HTTP/1.1 path:\n\n- Jetty explicitly checks whether authority and `Host` match\n- mismatches are rejected by default\n\n#### Relevant Code Locations\n\nHTTP/2 metadata builder:\n\n- `jetty-core/jetty-http2/jetty-http2-hpack/src/main/java/org/eclipse/jetty/http2/hpack/internal/MetaDataBuilder.java`\n\nHTTP/3 metadata builder:\n\n- `jetty-core/jetty-http3/jetty-http3-qpack/src/main/java/org/eclipse/jetty/http3/qpack/internal/metadata/MetaDataBuilder.java`\n\nHTTP/2 server entry:\n\n- `jetty-core/jetty-http2/jetty-http2-server/src/main/java/org/eclipse/jetty/http2/server/internal/HttpStreamOverHTTP2.java`\n\nHTTP/3 server entry:\n\n- `jetty-core/jetty-http3/jetty-http3-server/src/main/java/org/eclipse/jetty/http3/server/internal/HttpStreamOverHTTP3.java`\n\nShared HTTP compliance verification:\n\n- `jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/ComplianceUtils.java`\n\nHTTP/1.1 authority/Host consistency check:\n\n- `jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/HttpConnection.java`\n\nDefined but not enforced on H2/H3:\n\n- `jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpCompliance.java`\n- violation: MISMATCHED_AUTHORITY\n\n#### Reproduction\n\nI reproduced this on local Jetty 12.1.9-SNAPSHOT source.\n\nMinimal reproduction steps:\n\n1. Start a Jetty HTTP/2 or HTTP/3 test server.\n2. Send a request with:\n    - :authority = localhost:\u003cport\u003e\n    - Host = evil.example:\u003cport\u003e\n3. In the request handler, inspect both:\n    - Request.getServerName(request)\n    - request.getHeaders().get(HttpHeader.HOST)\n4. Observe whether Jetty rejects the request or allows both values to remain visible.\nObserved result:\n    - HTTP/2: request is accepted and returns 200\n    - HTTP/3: request is accepted and returns 200\n    - the server can observe both:\n        - serverName=localhost\n        - hostHeader=evil.example:\u003cport\u003e\n\nThis shows that a single attacker-controlled request can preserve two conflicting host interpretations inside Jetty.\n\n#### Tests Used\n\n\nHTTP/2 rejection test:\n\n- `org.eclipse.jetty.http2.tests.HTTP2Test#testRejectMismatchedHostHeaderAndAuthority`\n\nHTTP/2 exploitability test:\n\n- `org.eclipse.jetty.http2.tests.HTTP2Test#testMismatchedHostHeaderAndAuthoritySplitsAuthorityFromHostHeader`\n\nHTTP/3 rejection test:\n\n- `org.eclipse.jetty.http3.tests.HandlerClientServerTest#testRejectMismatchedHostHeaderAndAuthority`\n\nHTTP/3 exploitability test:\n\n- `org.eclipse.jetty.http3.tests.HandlerClientServerTest#testMismatchedHostHeaderAndAuthoritySplitsAuthorityFromHostHeader`\n\n\nObserved behavior:\n\n- both rejection tests fail because Jetty returns 200 instead of 400\n- both exploitability tests pass, confirming that Jetty exposes different host values to different layers\n\n#### Project-Internal Evidence of Real Impact\n\nExamples:\n\n- `jetty-openid` uses `Request.getServerName(request)` to construct redirect URLs\n- `jetty-ee11-proxy` uses the raw `Host` header when building `Forwarded`\n\nThis indicates that the issue is not merely theoretical: Jetty’s own\necosystem already contains code paths where different host sources are\nused for different purposes.\n\n#### Affected Version\n\nConfirmed affected version:\n\n- 12.1.9-SNAPSHOT\n\nOther versions may also be affected if they share the same HTTP/2 /\nHTTP/3 request construction and compliance-validation logic. I have\nnot yet completed a historical version matrix and would recommend\nconfirming exact affected ranges from Jetty’s branch history.\n\n\n#### Suggested Fix\n\nRecommend adding HTTP/2 and HTTP/3 validation equivalent to the\nexisting HTTP/1.1 authority/Host consistency check:\n\n- if both :authority and regular Host are present\n    - normalize and compare them\n    - if they do not match, reject the request with 400 Bad Request\n    - route the failure through the existing MISMATCHED_AUTHORITY compliance mechanism\n\nAlso adding explicit HTTP/2 and HTTP/3 regression coverage for this case.\n\n#### Disclosure Status\n\n- not publicly disclosed\n- no public issue filed\n- shared only privately with the Jetty security contacts","aliases":["CVE-2026-6790"],"modified":"2026-07-22T23:25:40.246011Z","published":"2026-07-22T22:56:43Z","database_specific":{"github_reviewed_at":"2026-07-22T22:56:43Z","nvd_published_at":"2026-07-14T09:16:41Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6790"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/issues/14870"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/pull/14871"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/pull/14897"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/pull/14970"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc"},{"type":"PACKAGE","url":"https://github.com/jetty/jetty.project"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.4.0.v20161208"},{"last_affected":"9.4.58.v20250814"}]}],"versions":["9.4.0.v20161208","9.4.0.v20180619","9.4.1.v20170120","9.4.1.v20180619","9.4.10.RC0","9.4.10.RC1","9.4.10.v20180503","9.4.11.v20180605","9.4.12.RC0","9.4.12.RC1","9.4.12.RC2","9.4.12.v20180830","9.4.13.v20181111","9.4.14.v20181114","9.4.15.v20190215","9.4.16.v20190411","9.4.17.v20190418","9.4.18.v20190429","9.4.19.v20190610","9.4.2.v20170220","9.4.2.v20180619","9.4.20.v20190813","9.4.21.v20190926","9.4.22.v20191022","9.4.23.v20191118","9.4.24.v20191120","9.4.25.v20191220","9.4.26.v20200117","9.4.27.v20200227","9.4.28.v20200408","9.4.29.v20200521","9.4.3.v20170317","9.4.3.v20180619","9.4.30.v20200611","9.4.31.v20200723","9.4.32.v20200930","9.4.33.v20201020","9.4.34.v20201102","9.4.35.v20201120","9.4.36.v20210114","9.4.37.v20210219","9.4.38.v20210224","9.4.39.v20210325","9.4.4.v20170414","9.4.4.v20180619","9.4.40.v20210413","9.4.41.v20210516","9.4.42.v20210604","9.4.43.v20210629","9.4.44.v20210927","9.4.45.v20220203","9.4.46.v20220331","9.4.47.v20220610","9.4.48.v20220622","9.4.49.v20220914","9.4.5.v20170502","9.4.5.v20180619","9.4.50.v20221201","9.4.51.v20230217","9.4.52.v20230823","9.4.53.v20231009","9.4.54.v20240208","9.4.55.v20240627","9.4.56.v20240826","9.4.57.v20241219","9.4.58.v20250814","9.4.6.v20170531","9.4.6.v20180619","9.4.7.RC0","9.4.7.v20170914","9.4.7.v20180619","9.4.8.v20171121","9.4.8.v20180619","9.4.9.v20180320"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7p3p-8qv8-m2vh/GHSA-7p3p-8qv8-m2vh.json"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"last_affected":"10.0.26"}]}],"versions":["10.0.0","10.0.1","10.0.10","10.0.11","10.0.12","10.0.13","10.0.14","10.0.15","10.0.16","10.0.17","10.0.18","10.0.19","10.0.2","10.0.20","10.0.21","10.0.22","10.0.23","10.0.24","10.0.25","10.0.26","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8","10.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7p3p-8qv8-m2vh/GHSA-7p3p-8qv8-m2vh.json"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"last_affected":"11.0.26"}]}],"versions":["11.0.0","11.0.1","11.0.10","11.0.11","11.0.12","11.0.13","11.0.14","11.0.15","11.0.16","11.0.17","11.0.18","11.0.19","11.0.2","11.0.20","11.0.21","11.0.22","11.0.23","11.0.24","11.0.25","11.0.26","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7p3p-8qv8-m2vh/GHSA-7p3p-8qv8-m2vh.json"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.0.35"}]}],"versions":["12.0.0","12.0.1","12.0.10","12.0.11","12.0.12","12.0.13","12.0.14","12.0.15","12.0.16","12.0.17","12.0.18","12.0.19","12.0.2","12.0.20","12.0.21","12.0.22","12.0.23","12.0.24","12.0.25","12.0.26","12.0.27","12.0.28","12.0.29","12.0.3","12.0.30","12.0.31","12.0.32","12.0.33","12.0.34","12.0.4","12.0.5","12.0.6","12.0.7","12.0.8","12.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.0.34","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7p3p-8qv8-m2vh/GHSA-7p3p-8qv8-m2vh.json"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.1.0"},{"fixed":"12.1.9"}]}],"versions":["12.1.0","12.1.1","12.1.2","12.1.3","12.1.4","12.1.5","12.1.6","12.1.7","12.1.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.1.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7p3p-8qv8-m2vh/GHSA-7p3p-8qv8-m2vh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}