Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1605

Опубликовано: 05 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.

A flaw was found in org.eclipse.jetty. A remote attacker can exploit this vulnerability by sending a compressed HTTP request with Content-Encoding: gzip when the server's response is not compressed. This prevents the release of the JDK Inflater, leading to a resource leak. This resource exhaustion can result in a Denial of Service (DoS), making the server unavailable to legitimate users.

Отчет

This Important flaw in Eclipse Jetty's GzipHandler can lead to a denial of service in affected Red Hat products. The vulnerability arises when compressed HTTP requests are processed without a corresponding compressed response, causing a resource leak that can exhaust system resources and render the service unavailable.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected
Red Hat build of Apache Camel for Spring Boot 4jetty-serverNot affected
Red Hat build of Apicurio Registry 2jetty-serverNot affected
Red Hat build of Apicurio Registry 3jetty-serverNot affected
Red Hat build of Debezium 2jetty-serverNot affected
Red Hat build of Debezium 3jetty-serverNot affected
Red Hat Data Grid 8jetty-serverNot affected
Red Hat Enterprise Linux 7maven-wagonNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2444815org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests

EPSS

Процентиль: 50%
0.00666
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.

CVSS3: 7.5
nvd
7 месяцев назад

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.

CVSS3: 7.5
debian
7 месяцев назад

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class Gzi ...

CVSS3: 7.5
github
7 месяцев назад

The Eclipse Jetty Server Artifact has a Gzip request memory leak

EPSS

Процентиль: 50%
0.00666
Низкий

7.5 High

CVSS3