Eclipse
Eclipse Jetty: vulnerabilidades y CVE
Eclipse Jetty tiene 60 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE60
Últimos 12 meses12
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34151 | Alta (8.2) | 1.1% | — | 14 sept 2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application… |
| CVE-2026-12611 | Alta (8.7) | 0.25% | — | 8 sept 2026 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a… |
| CVE-2026-19204 | Alta (8.7) | 0.31% | — | 7 sept 2026 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when… |
| CVE-2026-10050 | Alta (8.7) | 0.63% | — | 4 ago 2026 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it… |
| CVE-2026-8384 | Media (5.3) | 0.33% | — | 14 jul 2026 | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will… |
| CVE-2026-6790 | Media (5.3) | 0.31% | — | 14 jul 2026 | In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP… |
| CVE-2026-10051 | Media (6.9) | 0.30% | — | 14 jul 2026 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the… |
| CVE-2024-7708 | Alta (7.5) | 0.44% | — | 14 jul 2026 | For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak. |
| CVE-2026-2332 | Crítica (9.1) | 1.3% | — | 14 abr 2026 | Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how… |
| CVE-2026-5795 | Alta (7.4) | 0.61% | — | 8 abr 2026 | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the… |
| CVE-2026-1605 | Alta (7.5) | 0.67% | — | 5 mar 2026 | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not… |
| CVE-2025-11143 | Media (6.5) | 0.16% | — | 5 mar 2026 | The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For… |
| CVE-2025-5115 | Alta (7.7) | 3.6% | — | 20 ago 2025 | In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should… |
| CVE-2025-41242 | Media (5.9) | 2.1% | — | 18 ago 2025 | Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: We have… |
| CVE-2025-1948 | Alta (7.5) | 0.75% | — | 8 may 2025 | In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation… |
| CVE-2024-13009 | Alta (7.2) | 0.53% | — | 8 may 2025 | In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between… |
| CVE-2024-8184 | Media (6.5) | 1.0% | — | 14 oct 2024 | There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests,… |
| CVE-2024-6763 | Media (5.3) | 0.97% | — | 14 oct 2024 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority… |
| CVE-2024-6762 | Media (6.5) | 0.94% | — | 14 oct 2024 | Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory. |
| CVE-2024-9823 | Alta (7.5) | 0.94% | — | 14 oct 2024 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted… |
| CVE-2024-38816 | Alta (7.5) | 15% | — | 13 sept 2024 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file… |
| CVE-2024-31851 | Alta (8.6) | 2.9% | — | 5 abr 2024 | A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive… |
| CVE-2024-31850 | Alta (8.6) | 3.0% | — | 5 abr 2024 | A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive… |
| CVE-2024-31848 | Crítica (9.8) | 8.1% | — | 5 abr 2024 | A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete… |
| CVE-2024-22201 | Alta (7.5) | 1.4% | — | 26 feb 2024 | Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and… |
| CVE-2023-36478 | Alta (7.5) | 3.8% | — | 10 oct 2023 | Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-41900 | Media (4.3) | 0.92% | — | 15 sept 2023 | Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`,… |
| CVE-2023-40167 | Media (5.3) | 1.3% | — | 15 sept 2023 | Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more… |
| CVE-2023-36479 | Baja (3.1) | 1.2% | — | 15 sept 2023 | Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.