Visit Jetty Home Page

NES for Jetty 10.0.x Release Notes

7 versions

Comprehensive release notes and changelog for NES for Jetty 10.0.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 25, 2026
Latest: 10.0.32
8 Patched Vulnerabilities
VEX Statements

August 2026

Full Version:
10.0.32

Security Fixes

  • Fixed a condition where threads could remain blocked when handling reset HTTP/2 requests (CVE-2026-12611).
  • Fixed HTTP request smuggling caused by lax parsing of LF terminators in chunked transfer-encoding extensions in jetty-http (CVE-2026-19203).
  • Fixed a WebSocket flaw where a reserved opcode could bypass the frame-size limit, leading to out-of-memory (OOM) (CVE-2026-19204).

10.0.31.1

Released Aug 7, 2026
Full Version:
10.0.31.1

Security Fixes

  • Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143).

July 2026

10.0.31

Released Jul 15, 2026
Full Version:
10.0.31

Security Fixes

  • Digest Authentication bypass via ISO-8859-1 character encoding collision (CVE-2026-10050).

10.0.30

Released Jul 15, 2026
Full Version:
10.0.30

Security Fixes

  • Missing validation of HTTP request authority against the Host header, potentially leading to incorrect URI construction and virtual host selection (CVE-2026-6790).

April 2026

10.0.29

Released Apr 10, 2026
Full Version:
10.0.29

Security Fixes

March 2026

10.0.28

Released Mar 6, 2026
Full Version:
10.0.28

Security Fixes

  • HTTP Request Smuggling via Chunked Extension Quoted-String Parsing (CVE-2026-2332).

10.0.27

Released Mar 5, 2026
Full Version:
10.0.27

Security Fixes

  • Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143). (Resolved in 10.0.31.1)

Notes

  • This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty 10.0.26.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.