Visit Jetty Home Page

Jetty 10.0.x Release Notes

6 versions

Comprehensive release notes and changelog for Jetty 10.0.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 7, 2026
Latest: 10.0.31.1
16 Patched Vulnerabilities
VEX Statements

August 2026

10.0.31.1

Released Aug 7, 2026
Full Version:
10.0.31.1

Security Fixes

  • Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143).

July 2026

10.0.31

Released Jul 15, 2026
Full Version:
10.0.31

Security Fixes

  • Digest Authentication bypass via ISO-8859-1 character encoding collision (CVE-2026-10050).

10.0.30

Released Jul 15, 2026
Full Version:
10.0.30

Security Fixes

  • Missing validation of HTTP request authority against the Host header, potentially leading to incorrect URI construction and virtual host selection (CVE-2026-6790).

April 2026

10.0.29

Released Apr 10, 2026
Full Version:
10.0.29

Security Fixes

March 2026

10.0.28

Released Mar 6, 2026
Full Version:
10.0.28

Security Fixes

  • HTTP Request Smuggling via Chunked Extension Quoted-String Parsing (CVE-2026-2332).

10.0.27

Released Mar 5, 2026
Full Version:
10.0.27

Security Fixes

  • Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143). (Resolved in 10.0.31.1)

Notes

  • This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty 10.0.26.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.