HIGH7.5CVE-2026-1605The Eclipse Jetty Server Artifact has a Gzip request memory leak from 0
from 0, < 12.0.17-3.1~deb13u1
from 0, < 12.0.17-3.1~deb13u1
HIGH7.5Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
from 0, < 12.0.17-1
HIGH7.4Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
from 0
HIGH7.4Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
from 0
MEDIUM5.3In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt inst…
from 0
MEDIUM5.3In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what…
from 0
LOW3.7org.eclipse.jetty:jetty-http has different parsing of invalid URIs
from 0