---
id: CVE-2024-7708
aliases:
  - GHSA-9299-c6m4-mjhc
title: 'Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests'
summary: 'Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests'
severity: high
cvss: 7.5
cwe:
  - CWE-400
  - CWE-401
vendor: eclipse
product: 'org.eclipse.jetty:jetty-server'
ecosystem: maven
affected:
  - 'org.eclipse.jetty:jetty-server >= 10.0.7, < 10.0.23'
  - 'org.eclipse.jetty:jetty-server >= 11.0.7, < 11.0.23'
patched:
  - 'org.eclipse.jetty:jetty-server 10.0.23'
  - 'org.eclipse.jetty:jetty-server 11.0.23'
published: '2026-07-22'
updated: '2026-07-22'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-9299-c6m4-mjhc'
references:
  - url: >-
      https://github.com/jetty/jetty.project/security/advisories/GHSA-9299-c6m4-mjhc
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-7708'
  - url: 'https://github.com/jetty/jetty.project/pull/12156'
  - url: >-
      https://github.com/jetty/jetty.project/commit/8259eabbc70ae7fc2d525f1e95b43fbdfd2ad097
  - url: 'https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.23'
  - url: 'https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.23'
  - url: 'https://gitlab.eclipse.org/security/cve-assignment/-/work_items/29'
  - url: 'https://github.com/advisories/GHSA-9299-c6m4-mjhc'
tags:
  - ghsa
  - maven
epss: 0.0044
epssPercentile: 0.37725
ingestedAt: '2026-07-22T23:07:32.330Z'
---

## Overview

### Impact
The original report:

> Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.

After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer.
This is particularly the case for 100-Continue, but any request where the network is slow can leak.

### Affected Versions

* Jetty 11.0.0-11.0.22 (EOL)
* Jetty 10.0.0-10.0.22 (EOL)

### Patched Versions

* Jetty 11.0.23
* Jetty 10.0.23

### Patches

https://github.com/jetty/jetty.project/pull/12156

### Workarounds

No workarounds.

## Affected packages

- `org.eclipse.jetty:jetty-server >= 10.0.7, < 10.0.23`
- `org.eclipse.jetty:jetty-server >= 11.0.7, < 11.0.23`

## Remediation

Upgrade to a patched release:

- `org.eclipse.jetty:jetty-server 10.0.23`
- `org.eclipse.jetty:jetty-server 11.0.23`
