Eclipse / Jetty
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-10050 | Digest authentication lossy encoding | HIGH | 8.7 | Aug 4, 2026 |
| CVE-2024-7708 | jetty: Eclipse Jetty: Denial of Service due to buffer leak in handling certain HTTP requests | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications | MEDIUM | 5.3 | Jul 14, 2026 |
| CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues | MEDIUM | 5.3 | Jul 14, 2026 |
| CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections | MEDIUM | 6.9 | Jul 14, 2026 |
| CVE-2026-2332 | HTTP Request Smuggling via Chunked Extension Quoted-String Parsing | CRITICAL | 9.1 | Apr 14, 2026 |
| CVE-2026-5795 | org.eclipse.jetty.ee10/jetty-ee10: early return from the JASPIAuthenticator class without clearing ThreadLocal variables | HIGH | 7.4 | Apr 8, 2026 |
| CVE-2026-1605 | org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests | HIGH | 7.5 | Mar 5, 2026 |
| CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing | MEDIUM | 6.5 | Mar 5, 2026 |
| CVE-2025-5115 | MadeYouReset HTTP/2 vulnerability | HIGH | 7.7 | Aug 20, 2025 |
| CVE-2025-1948 | Eclipse Jetty HTTP clients can increase memory allocation | HIGH | 7.5 | May 8, 2025 |
| CVE-2024-13009 | Eclipse Jetty GZIP buffer release | HIGH | 7.2 | May 8, 2025 |
| CVE-2024-8184 | Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks | MEDIUM | 6.5 | Oct 14, 2024 |
| CVE-2024-6762 | Jetty PushSessionCacheFilter can cause remote DoS attacks | LOW | 2.3 | Oct 14, 2024 |
| CVE-2024-6763 | Jetty URI parsing of invalid authority | MEDIUM | 6.3 | Oct 14, 2024 |
| CVE-2024-9823 | Jetty DOS vulnerability on DosFilter | HIGH | 7.5 | Oct 14, 2024 |
| CVE-2024-22201 | Jetty connection leaking on idle timeout when TCP congested | HIGH | 7.5 | Feb 26, 2024 |
| CVE-2023-36478 | HTTP/2 HPACK integer overflow and buffer allocation | HIGH | 7.5 | Oct 10, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-41900 | Jetty's OpenId Revoked authentication allows one request | MEDIUM | 4.3 | Sep 15, 2023 |
| CVE-2023-40167 | Jetty accepts "+" prefixed value in Content-Length | MEDIUM | 5.3 | Sep 15, 2023 |
| CVE-2023-36479 | Jetty vulnerable to errant command quoting in CGI Servlet | LOW | 3.5 | Sep 15, 2023 |
| CVE-2023-26049 | Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty | MEDIUM | 5.3 | Apr 18, 2023 |
| CVE-2023-26048 | OutOfMemoryError for large multipart without filename in Eclipse Jetty | MEDIUM | 5.3 | Apr 18, 2023 |
| CVE-2022-2191 | jetty-server: Improper release of ByteBuffers in SslConnections | HIGH | 7.5 | Jul 7, 2022 |
Showing 1 to 25 of 52 CVEs