Eclipse Jetty HTTP clients can increase memory allocation
Published May 8, 2025
7.5
HIGHCVSS 3.1
EPSS 0.75%
Description
In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
Affected products
-
- Version 12.0.0StatusaffectedConstraints<=12.0.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Eclipse Foundation | Jetty | unaffected |
|
No data.
OCP-Tools-4.12-RHEL-8
jenkins-0:2.504.2.1750932984-3.el8
Fixed · RHSA-2025:10118
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1750933270-1.el8
Fixed · RHSA-2025:10118
OCP-Tools-4.13-RHEL-8
jenkins-0:2.504.2.1750916374-3.el8
Fixed · RHSA-2025:10119
OCP-Tools-4.13-RHEL-8
jenkins-2-plugins-0:4.13.1750916671-1.el8
Fixed · RHSA-2025:10119
OCP-Tools-4.14-RHEL-8
jenkins-0:2.504.2.1750903189-3.el8
Fixed · RHSA-2025:10120
OCP-Tools-4.14-RHEL-8
jenkins-2-plugins-0:4.14.1750903529-1.el8
Fixed · RHSA-2025:10120
OCP-Tools-4.15-RHEL-8
jenkins-0:2.504.2.1750856366-3.el8
Fixed · RHSA-2025:10104
OCP-Tools-4.15-RHEL-8
jenkins-2-plugins-0:4.15.1750856638-1.el8
Fixed · RHSA-2025:10104
OCP-Tools-4.16-RHEL-9
jenkins-0:2.504.2.1750857144-3.el9
Fixed · RHSA-2025:10098
OCP-Tools-4.16-RHEL-9
jenkins-2-plugins-0:4.16.1750857315-1.el9
Fixed · RHSA-2025:10098
OCP-Tools-4.17-RHEL-9
jenkins-0:2.504.2.1750851690-3.el9
Fixed · RHSA-2025:10097
OCP-Tools-4.17-RHEL-9
jenkins-2-plugins-0:4.17.1750851950-1.el9
Fixed · RHSA-2025:10097
OCP-Tools-4.18-RHEL-9
jenkins-0:2.504.2.1750846524-3.el9
Fixed · RHSA-2025:10092
OCP-Tools-4.18-RHEL-9
jenkins-2-plugins-0:4.18.1750846854-1.el9
Fixed · RHSA-2025:10092
Red Hat AMQ Broker 7.13.1
jetty-http2-common
Fixed · RHSA-2025:13274
Red Hat build of Apache Camel 4.10.3 for Spring Boot
jetty-http2-common
Fixed · RHSA-2025:7696
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.12-RHEL-8 | jenkins-0:2.504.2.1750932984-3.el8 | Fixed | RHSA-2025:10118 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1750933270-1.el8 | Fixed | RHSA-2025:10118 |
| OCP-Tools-4.13-RHEL-8 | jenkins-0:2.504.2.1750916374-3.el8 | Fixed | RHSA-2025:10119 |
| OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins-0:4.13.1750916671-1.el8 | Fixed | RHSA-2025:10119 |
| OCP-Tools-4.14-RHEL-8 | jenkins-0:2.504.2.1750903189-3.el8 | Fixed | RHSA-2025:10120 |
| OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins-0:4.14.1750903529-1.el8 | Fixed | RHSA-2025:10120 |
| OCP-Tools-4.15-RHEL-8 | jenkins-0:2.504.2.1750856366-3.el8 | Fixed | RHSA-2025:10104 |
| OCP-Tools-4.15-RHEL-8 | jenkins-2-plugins-0:4.15.1750856638-1.el8 | Fixed | RHSA-2025:10104 |
| OCP-Tools-4.16-RHEL-9 | jenkins-0:2.504.2.1750857144-3.el9 | Fixed | RHSA-2025:10098 |
| OCP-Tools-4.16-RHEL-9 | jenkins-2-plugins-0:4.16.1750857315-1.el9 | Fixed | RHSA-2025:10098 |
| OCP-Tools-4.17-RHEL-9 | jenkins-0:2.504.2.1750851690-3.el9 | Fixed | RHSA-2025:10097 |
| OCP-Tools-4.17-RHEL-9 | jenkins-2-plugins-0:4.17.1750851950-1.el9 | Fixed | RHSA-2025:10097 |
| OCP-Tools-4.18-RHEL-9 | jenkins-0:2.504.2.1750846524-3.el9 | Fixed | RHSA-2025:10092 |
| OCP-Tools-4.18-RHEL-9 | jenkins-2-plugins-0:4.18.1750846854-1.el9 | Fixed | RHSA-2025:10092 |
| Red Hat AMQ Broker 7.13.1 | jetty-http2-common | Fixed | RHSA-2025:13274 |
| Red Hat build of Apache Camel 4.10.3 for Spring Boot | jetty-http2-common | Fixed | RHSA-2025:7696 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 8, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.75% (0.00748) | 53.20th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.63% (0.00625) | 45.05th | v5 (v2026.06.15) |
| May 9, 2025 | 0.04% (0.00040) | 11.60th | v4 (v2025.03.14) |
References (9)
- https://access.redhat.com/security/cve/CVE-2025-1948 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2365137 Issue Tracking
- https://github.com/advisories/GHSA-889j-63jv-qhr8 Advisory
- https://github.com/jetty/jetty.project/commit/c8c2515936ef968dc8a3cecd9e79d1e69291e4bb
- https://github.com/jetty/jetty.project/issues/12690
- https://github.com/jetty/jetty.project/security/advisories/GHSA-889j-63jv-qhr8 Vendor Advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/56 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-1948
- https://www.cve.org/CVERecord?id=CVE-2025-1948
Change history (0)
No recorded changes yet.