THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-5795 (HIGH 7.4) — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

[NVD] CVE-2026-5795 (HIGH 7.4) — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

lownvdPublished 2026-04-08

CVE-2026-5795 CVSS: 7.4 HIGH Published: 2026-04-08T14:16:32.633

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.

Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

A subsequent request using the same thread inherits t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5795