CVE-2026-10051

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.


We have discovered 733 live websites that are affected by CVE-2026-10051.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains733 live websites (15% of Jetty install base)
Vulnerable Versions
  • from 12 through 12.0.35
  • from 12.1 through 12.1.9
Vulnerable Versions Count30 versions ( 14% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Website Distribution by Country

Number of websites using CVE-2026-10051
United States411 websites



Germany83 websites
Switzerland76 websites
Sweden29 websites
GB19 websites
Czech Republic12 websites
Australia10 websites
Canada10 websites
European Union9 websites
Netherlands9 websites

Website Distribution by TLD

Number of websites using CVE-2026-10051
.com167 websites
.ch81 websites
.org50 websites
.de45 websites
.se44 websites
.edu37 websites
.net16 websites
.nl15 websites
.it13 websites
.cz12 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-10051

Top websites that are affected by CVE-2026-10051. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.******.edu United States***
***.********.edu United States***
**.**********.com United States**,***
****.**.**.se Sweden**,***
**********.********.edu United States**,***
**********.****.edu United States**,***
*****.**.edu United States***,***
****.****.edu United States***,***
*****.***********.org United States***,***
***************.********.com United States***,***
See full domain list

FAQ

CVE-2026-10051 is Exposure of Sensitive Information to an Unauthorized Actor in Jetty
A total of 733 websites have been identified as vulnerable to CVE-2026-10051, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2026-10051 vulnerability.
Jetty versions up to and including 12.1.9 are vulnerable to CVE-2026-10051.