CVE-2026-6790 affects multiple packages. In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). See references for individual vulnerability details.