CVE-2025-5115
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.
Leer descripción completaMostrar menos
The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.
The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.
Links:
Detalles técnicos trazas, registros y código del informe original
* https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 7.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.63%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Vector AV:N/PR:N/UI:N indica explotación remota sin privilegios (T1190). HTTP/2 malformado causa agotamiento de recursos del servidor (T1499.004 - application exhaustion).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-400
Referencias
- https://github.com/jetty/jetty.project/pull/13449
- https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.26
- https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.26
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25
- https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.0
- https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.58.v20250814
- https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
- http://www.openwall.com/lists/oss-security/2025/08/20/4
- http://www.openwall.com/lists/oss-security/2025/09/17/1
- https://lists.debian.org/debian-lts-announce/2025/09/msg00014.html
- https://www.kb.cert.org/vuls/id/767506
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-5115",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-5115",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-08-20T19:28:04.700843Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 7.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"repo": "https://github.com/jetty/jetty.project",
"vendor": "Eclipse Jetty",
"product": "Eclipse Jetty",
"versions": [
{
"status": "affected",
"version": ">=9.3.0",
"versionType": "semver",
"lessThanOrEqual": "<=9.4.57"
},
{
"status": "affected",
"version": ">=10.0.0",
"versionType": "semver",
"lessThanOrEqual": "<=10.0.25"
},
{
"status": "affected",
"version": ">=11.0.0",
"versionType": "semver",
"lessThanOrEqual": "<=11.0.25"
},
{
"status": "affected",
"version": ">=12.0.0",
"versionType": "semver",
"lessThanOrEqual": "<=12.0.21"
},
{
"status": "affected",
"version": ">=12.1.0.alpha0",
"versionType": "semver",
"lessThanOrEqual": "<=12.1.0.alpha2"
}
],
"packageName": "pkg:maven/org.eclipse.jetty.http2/http2-common",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-08-20T20:15:33.377",
"references": [
{
"url": "https://github.com/jetty/jetty.project/pull/13449",
"tags": [
"Issue Tracking"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.26",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.26",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.0",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.58.v20250814",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h",
"tags": [
"Third Party Advisory"
],
"source": "emo@eclipse.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2025/08/20/4",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2025/09/17/1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/09/msg00014.html",
"tags": [
"Issue Tracking",
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kb.cert.org/vuls/id/767506",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.\n\n\nFor example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.\nPer specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.\nThe client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.\n\n\nThe attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.\n\n\n\nLinks:\n\n\n\n * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h"
},
{
"lang": "es",
"value": "En Eclipse Jetty, versiones <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, un cliente HTTP/2 puede provocar que el servidor envíe tramas RST_STREAM, por ejemplo, enviando tramas con formato incorrecto o que no deberían enviarse en un estado de flujo específico, lo que obliga al servidor a consumir recursos como CPU y memoria. Por ejemplo, un cliente puede abrir un flujo y luego enviar tramas WINDOW_UPDATE con un incremento de tamaño de ventana de 0, lo cual es ilegal. Según la especificación https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update, el servidor debe enviar una trama RST_STREAM. El cliente ahora puede abrir otra transmisión y enviar otra WINDOW_UPDATE incorrecta, lo que provoca que el servidor consuma más recursos de los necesarios. En este caso, no se supera el número máximo de transmisiones simultáneas, pero el cliente puede crear una enorme cantidad de transmisiones en poco tiempo. El ataque puede ejecutarse con otras condiciones (por ejemplo, una trama DATA para una transmisión cerrada) que provocan que el servidor envíe una trama RST_STREAM. Enlaces: * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h"
}
],
"lastModified": "2026-06-17T09:47:13.537",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F512BB3-9D38-43E0-9962-876DA3232AE2",
"versionEndIncluding": "9.4.57",
"versionStartIncluding": "9.3.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDD3D394-58B1-4E91-8F5C-E343F6EB4108",
"versionEndIncluding": "10.0.25",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B8C48CF-A987-4C4C-A1B5-8E6B2D321DAB",
"versionEndIncluding": "11.0.25",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B535FBFA-91E1-4E8E-8731-1671DEA66413",
"versionEndIncluding": "12.0.21",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E708B1F-1405-48BA-8B32-9611D491286C"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A837B906-9792-4AFA-8391-C8A00913E1D7"
},
{
"criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8D7F1B4-3C3F-48FF-A7F0-C5462171E6EA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "emo@eclipse.org"
}