Incorrect Implementation of Authentication Algorithm Affecting satellite:el8/puppetserver package, versions *


Severity

Recommended
high

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.47% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-SATELLITE-18680973
  • published12 Aug 2026
  • disclosed16 Jul 2026

Introduced: 16 Jul 2026

NewCVE-2026-10050  (opens in a new tab)
CWE-303  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:7 satellite:el8/puppetserver.

NVD Description

Note: Versions mentioned in the description apply only to the upstream satellite:el8/puppetserver package and not the satellite:el8/puppetserver package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.

This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.

If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by ?. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: αβ123 converts to ??123.

An attacker can send a request with a digest Authorization header crafted with a password made of only ? characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.

Recent HTTP Digest RFC-7616 supports a charset parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

CVSS Base Scores

version 3.1