« Volver al listado

CVE-2025-5115

Estado: AnalizadaAlta (7.7)—

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.

For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.

Leer descripción completaMostrar menos

The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.

The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.

Links:

Detalles técnicos trazas, registros y código del informe original
  *   https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/PR:N/UI:N indica explotación remota sin privilegios (T1190). HTTP/2 malformado causa agotamiento de recursos del servidor (T1499.004 - application exhaustion).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-5115",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-5115",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-20T19:28:04.700843Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "emo@eclipse.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "emo@eclipse.org",
      "affectedData": [
        {
          "repo": "https://github.com/jetty/jetty.project",
          "vendor": "Eclipse Jetty",
          "product": "Eclipse Jetty",
          "versions": [
            {
              "status": "affected",
              "version": ">=9.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "<=9.4.57"
            },
            {
              "status": "affected",
              "version": ">=10.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "<=10.0.25"
            },
            {
              "status": "affected",
              "version": ">=11.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "<=11.0.25"
            },
            {
              "status": "affected",
              "version": ">=12.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "<=12.0.21"
            },
            {
              "status": "affected",
              "version": ">=12.1.0.alpha0",
              "versionType": "semver",
              "lessThanOrEqual": "<=12.1.0.alpha2"
            }
          ],
          "packageName": "pkg:maven/org.eclipse.jetty.http2/http2-common",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-20T20:15:33.377",
  "references": [
    {
      "url": "https://github.com/jetty/jetty.project/pull/13449",
      "tags": [
        "Issue Tracking"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.26",
      "tags": [
        "Release Notes"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.26",
      "tags": [
        "Release Notes"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25",
      "tags": [
        "Release Notes"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.0",
      "tags": [
        "Release Notes"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.58.v20250814",
      "tags": [
        "Release Notes"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/08/20/4",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/09/17/1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/09/msg00014.html",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/767506",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "emo@eclipse.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.\n\n\nFor example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.\nPer specification  https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.\nThe client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.\n\n\nThe attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.\n\n\n\nLinks:\n\n\n\n  *   https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h"
    },
    {
      "lang": "es",
      "value": "En Eclipse Jetty, versiones &lt;=9.4.57, &lt;=10.0.25, &lt;=11.0.25, &lt;=12.0.21, &lt;=12.1.0.alpha2, un cliente HTTP/2 puede provocar que el servidor envíe tramas RST_STREAM, por ejemplo, enviando tramas con formato incorrecto o que no deberían enviarse en un estado de flujo específico, lo que obliga al servidor a consumir recursos como CPU y memoria. Por ejemplo, un cliente puede abrir un flujo y luego enviar tramas WINDOW_UPDATE con un incremento de tamaño de ventana de 0, lo cual es ilegal. Según la especificación https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update, el servidor debe enviar una trama RST_STREAM. El cliente ahora puede abrir otra transmisión y enviar otra WINDOW_UPDATE incorrecta, lo que provoca que el servidor consuma más recursos de los necesarios. En este caso, no se supera el número máximo de transmisiones simultáneas, pero el cliente puede crear una enorme cantidad de transmisiones en poco tiempo. El ataque puede ejecutarse con otras condiciones (por ejemplo, una trama DATA para una transmisión cerrada) que provocan que el servidor envíe una trama RST_STREAM. Enlaces: * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h"
    }
  ],
  "lastModified": "2026-06-17T09:47:13.537",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F512BB3-9D38-43E0-9962-876DA3232AE2",
              "versionEndIncluding": "9.4.57",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDD3D394-58B1-4E91-8F5C-E343F6EB4108",
              "versionEndIncluding": "10.0.25",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B8C48CF-A987-4C4C-A1B5-8E6B2D321DAB",
              "versionEndIncluding": "11.0.25",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B535FBFA-91E1-4E8E-8731-1671DEA66413",
              "versionEndIncluding": "12.0.21",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E708B1F-1405-48BA-8B32-9611D491286C"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A837B906-9792-4AFA-8391-C8A00913E1D7"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:12.1.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8D7F1B4-3C3F-48FF-A7F0-C5462171E6EA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "emo@eclipse.org"
}