Skip to main content

Vendor/product archive

eclipse / jetty CVEs

Beta · best-effort

51 CVEs tagged to eclipse / jetty4 Critical, 20 High, 18 Medium, 9 Low, 0 Unrated.

CVE-2026-8384

Published Jul 14, 2026

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the exp…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6790

Published Jul 14, 2026

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present)…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10051

Published Jul 14, 2026

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request tha…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-7708

Published Jul 14, 2026

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where th…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2332

Published Apr 14, 2026

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.…

CVSS 7.4 · High
evidence mentions
14
Buzz score
46.6
Vendor/product tagsBeta · best-effort

CVE-2026-5795

Published Apr 8, 2026

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditi…

CVSS 7.4 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-1605

Published Mar 5, 2026

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed an…

CVSS 7.5 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-11143

Published Mar 5, 2026

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components ma…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5115

Published Aug 20, 2025

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending fr…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1948

Published May 8, 2025

In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HT…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-13009

Published May 8, 2025

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8184

Published Oct 14, 2024

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By re…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6763

Published Oct 14, 2024

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insu…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6762

Published Oct 14, 2024

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40167

Published Sep 15, 2023

Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36479

Published Sep 15, 2023

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command exe…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26048

Published Apr 18, 2023

Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) that call `HttpServletRequest.ge…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2191

Published Jul 7, 2022

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code path…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2048

Published Jul 7, 2022

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active conne…

CVSS 7.5 · High
Showing 1-25 of 51 CVEsPage 1 of 3