VulnSea

eclipse_jetty vulnerabilities

CVEs whose affected-version data names the eclipse_jetty package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-19203High· 8.3
2w ago

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
CVE-2026-12611High· 8.7
2w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-19204High· 8.7
2w ago

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
eclipse_jetty vulnerabilities (CVEs) · VulnSea