THREAT OPS › Threat News › [NVD] CVE-2026-5795 (HIGH 7.4) — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.
[NVD] CVE-2026-5795 (HIGH 7.4) — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.
CVE-2026-5795 CVSS: 7.4 HIGH Published: 2026-04-08T14:16:32.633
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.
A subsequent request using the same thread inherits t
Indicators of compromise
- CVE-2026-5795cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5795