CVE-2026-12611
- EPSS 0.25%
- Veröffentlicht 08.09.2026 12:28:51
- Zuletzt bearbeitet 09.09.2026 11:17:12
A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race condition in the serv...
CVE-2026-19203
- EPSS 0.29%
- Veröffentlicht 08.09.2026 12:08:37
- Zuletzt bearbeitet 08.09.2026 15:18:42
A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accept...
CVE-2026-19204
- EPSS 0.29%
- Veröffentlicht 07.09.2026 10:19:24
- Zuletzt bearbeitet 08.09.2026 16:18:06
A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unkno...
CVE-2026-10050
- EPSS 0.47%
- Veröffentlicht 04.08.2026 11:02:40
- Zuletzt bearbeitet 08.08.2026 00:38:56
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 f...
CVE-2024-7708
- EPSS 0.26%
- Veröffentlicht 14.07.2026 09:01:53
- Zuletzt bearbeitet 02.10.2026 00:10:00
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
CVE-2026-8384
- EPSS 0.23%
- Veröffentlicht 14.07.2026 08:56:17
- Zuletzt bearbeitet 14.07.2026 18:39:51
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as ...
CVE-2026-6790
- EPSS 0.2%
- Veröffentlicht 14.07.2026 08:51:30
- Zuletzt bearbeitet 14.07.2026 18:35:54
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 26...
CVE-2026-10051
- EPSS 0.3%
- Veröffentlicht 14.07.2026 08:44:38
- Zuletzt bearbeitet 14.07.2026 18:41:52
In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subseq...
CVE-2026-2332
- EPSS 1.21%
- Veröffentlicht 14.04.2026 10:59:10
- Zuletzt bearbeitet 10.09.2026 13:18:03
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/fu...
CVE-2026-5795
- EPSS 0.53%
- Veröffentlicht 08.04.2026 13:32:28
- Zuletzt bearbeitet 14.09.2026 13:18:42
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without...