Package
solr-fips-9-iamguarded-compat
Component
jetty-http
Latest update
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The shipped jetty-http-10.0.26.jar already contains the upstream fix. GHSA-qh8g-58pp-2wxh lists only 12.0.12 as patched, but Jetty backported the HttpURI authority validation to 10.0.x in jetty/jetty.project#12874 ("Introduce UriCompliance.USER_INFO to Jetty 10.0.x", backport of 12.0.x commit c880d9309b), merged 2025-03-07 and first released in 10.0.25. HttpURI in the 10.0.26 tag now rejects illegal authority characters (#, ;, non-sub-delims, malformed %-encoding) with "Bad authority", which blocks the advisory's PoC payloads. The advisory's version range is inaccurate for the 10.0.x line.
Status