CVE-2026-6790

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112). This mismatch can cause a number of problems that may be classified as vulnerabilities such as: * URI constructions (for example, for redirects -- this is typical for login pages) * Virtual host selection * Reverse proxying * Misleading logs * Etc. Given that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.


We have discovered 2,835 live websites that are affected by CVE-2026-6790.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains2,835 live websites (57% of Jetty install base)
Vulnerable Versions
  • from 9.4 through 9.4.60
  • from 10 through 10.0.28
  • from 11 through 11.0.28
  • from 12 through 12.0.34
  • from 12.1 through 12.1.8
Vulnerable Versions Count110 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Website Distribution by Country

Number of websites using CVE-2026-6790
United States1,798 websites



Germany241 websites
France157 websites
Switzerland90 websites
GB56 websites
Canada50 websites
Sweden41 websites
China34 websites
Australia33 websites
Netherlands28 websites

Website Distribution by TLD

Number of websites using CVE-2026-6790
.com1,234 websites
.org220 websites
.edu155 websites
.net141 websites
.de114 websites
.fr105 websites
.ch91 websites
.se49 websites
.nl31 websites
.ca29 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-6790

Top websites that are affected by CVE-2026-6790. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.******.edu United States***
***.********.edu United States***
******.***********.net United States*,***
*.******.com United States**,***
**.**********.com United States**,***
*********.******.com United States**,***
********.org Germany**,***
*******.com United States**,***
**.****************.com United States**,***
********.dk United States**,***
See full domain list

FAQ

CVE-2026-6790 is Improper Input Validation in Jetty
A total of 2,835 websites have been identified as vulnerable to CVE-2026-6790, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2026-6790 vulnerability.
Jetty versions up to and including 12.1.8 are vulnerable to CVE-2026-6790.