Visit Jetty Home Page
NES for Jetty 9.4.x Release Notes
6 versions
Comprehensive release notes and changelog for NES for Jetty 9.4.x, including security patches, bug fixes, and feature updates across all supported versions.
August 2026
9.4.64
Released Aug 25, 2026 Full Version:
9.4.64
Security Fixes
- Fixed HTTP request smuggling caused by lax parsing of LF terminators in chunked transfer-encoding extensions in jetty-http (CVE-2026-19203).
- Fixed a condition where threads could remain blocked when handling reset HTTP/2 requests (CVE-2026-12611).
July 2026
9.4.63
Released Jul 15, 2026 Full Version:
9.4.63
Security Fixes
- Digest Authentication bypass via ISO-8859-1 character encoding collision (CVE-2026-10050).
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
9.4.58.
9.4.62
Released Jul 15, 2026 Full Version:
9.4.62
Security Fixes
- Missing validation of HTTP request authority against the
Hostheader, potentially leading to incorrect URI construction and virtual host selection (CVE-2026-6790).
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
9.4.58.
April 2026
9.4.61
Released Apr 10, 2026 Full Version:
9.4.61
Security Fixes
- JASPI access control escalation (CVE-2026-5795).
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
9.4.58.
March 2026
9.4.60
Released Mar 6, 2026 Full Version:
9.4.60
Security Fixes
- HTTP Request Smuggling via Chunked Extension Quoted-String Parsing (CVE-2026-2332).
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
9.4.58.
9.4.59
Released Mar 5, 2026 Full Version:
9.4.59
Security Fixes
- Fixed improper input validation in jetty-http where malformed URIs were parsed differently than other common parsers, potentially allowing blocklist bypass in multi-component systems (CVE-2025-11143).
Notes
- This release originates from the open-source Eclipse Jetty by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Jetty
9.4.58.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh