CVE-2026-8384

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.


We have discovered 708 live websites that are affected by CVE-2026-8384.

Run a Free Instant Scan




Affected Software

Product  Jetty
Category Web Servers
Vulnerable Domains708 live websites (14% of Jetty install base)
Vulnerable Versions
  • from 12 through 12.0.34
  • from 12.1 through 12.1.8
Vulnerable Versions Count28 versions ( 13% of all versions)


Common Weakness Enumeration

CWE-647 Use of Non-Canonical URL Paths for Authorization Decisions



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Credits

  • https://github.com/jweny (finder)
  • https://github.com/lworld0x00 (finder)

Website Distribution by Country

Number of websites using CVE-2026-8384
United States401 websites



Switzerland76 websites
Germany76 websites
Sweden26 websites
GB18 websites
Czech Republic12 websites
Australia10 websites
European Union9 websites
Canada9 websites
Netherlands9 websites

Website Distribution by TLD

Number of websites using CVE-2026-8384
.com158 websites
.ch81 websites
.org49 websites
.se41 websites
.de41 websites
.edu35 websites
.net16 websites
.nl15 websites
.it13 websites
.cz12 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-8384

Top websites that are affected by CVE-2026-8384. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.******.edu United States***
***.********.edu United States***
**.**********.com United States**,***
****.**.**.se Sweden**,***
**********.****.edu United States**,***
*****.**.edu United States***,***
****.****.edu United States***,***
*****.***********.org United States***,***
***************.********.com United States***,***
***.**********.com United States***,***
See full domain list

FAQ

CVE-2026-8384 is Use of Non-Canonical URL Paths for Authorization Decisions in Jetty
A total of 708 websites have been identified as vulnerable to CVE-2026-8384, based on global website indexing conducted by WebTechSurvey.
The Jetty is affected by the CVE-2026-8384 vulnerability.
Jetty versions up to and including 12.1.8 are vulnerable to CVE-2026-8384.