Visit Jetty Home Page
Jetty 10.0.x Release Notes
6 versions
Comprehensive release notes and changelog for Jetty 10.0.x, including security patches, bug fixes, and feature updates across all supported versions.
August 2026
10.0.31.1
Released Aug 7, 2026 Full Version:
10.0.31.1
Security Fixes
- Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143).
July 2026
10.0.31
Released Jul 15, 2026 Full Version:
10.0.31
Security Fixes
- Digest Authentication bypass via ISO-8859-1 character encoding collision (CVE-2026-10050).
10.0.30
Released Jul 15, 2026 Full Version:
10.0.30
Security Fixes
- Missing validation of HTTP request authority against the
Hostheader, potentially leading to incorrect URI construction and virtual host selection (CVE-2026-6790).
April 2026
10.0.29
Released Apr 10, 2026 Full Version:
10.0.29
Security Fixes
- JASPI access control escalation (CVE-2026-5795).
March 2026
10.0.28
Released Mar 6, 2026 Full Version:
10.0.28
Security Fixes
- HTTP Request Smuggling via Chunked Extension Quoted-String Parsing (CVE-2026-2332).
10.0.27
Released Mar 5, 2026 Full Version:
10.0.27
Security Fixes
Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143).(Resolved in 10.0.31.1)
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
10.0.26.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh