CLEANSTART-2026-BB15937

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-BB15937.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-BB15937
Upstream
Published
2026-10-08T00:38:12Z
Modified
2026-10-08T16:47:03Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present)
Details

CVE-2026-6790 affects multiple packages. In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). See references for individual vulnerability details.

References

Affected packages

CleanStart / apache-hive

Package

Name
apache-hive
Purl
pkg:apk/cleanstart/apache-hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-BB15937.json"

CleanStart / trino

Package

Name
trino
Purl
pkg:apk/cleanstart/trino

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
481-r5

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-BB15937.json"