CVE-2024-7708High· 7.5▾ TwilightEclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.4%
The original report:
Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.
After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
https://github.com/jetty/jetty.project/pull/12156
No workarounds.
org.eclipse.jetty:jetty-server >= 10.0.7, < 10.0.23org.eclipse.jetty:jetty-server >= 11.0.7, < 11.0.23Upgrade to a patched release:
org.eclipse.jetty:jetty-server 10.0.23org.eclipse.jetty:jetty-server 11.0.23Connected by shared product, vendor, weakness, or advisory.
CVE-2026-1605High· 7.5In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This hap…
CVE-2026-6790Medium· 5.3Eclipse Jetty: HTTP Authority/Host mismatch
CVE-2026-48043Medium· 5.3Netty is a network application framework for development of protocol servers and clients
CVE-2020-3572High· 8.6A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…
CVE-2020-3563High· 8.6A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…