In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.
The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.
Links:
* https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
CVSS Details
- CVSS 4.0 Base Score: 7.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jetty9Upgrade jetty12 | Sep 16, 2025 | Sep 16, 2025 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Dec 10, 2025 | Sep 17, 2025 |
| Jenkins 2025 09 17 | — | Upgrade Jenkins to version 2.528Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.516.3 | Sep 18, 2025 | Aug 20, 2025 |
| Red Hat Jboss Eap | — | — | Oct 15, 2025 | Aug 20, 2025 |
| Suse | — | Upgrade jetty-jmxUpgrade jetty-continuationUpgrade jetty-securityUpgrade jetty-util-ajaxUpgrade jetty-quickstartUpgrade jetty-minimal-javadocUpgrade jetty-javax-websocket-server-implUpgrade jetty-rewriteUpgrade jetty-utilUpgrade jetty-antUpgrade jetty-deployUpgrade jetty-openidUpgrade jetty-jspUpgrade jetty-projectUpgrade jetty-servletUpgrade jetty-serverUpgrade jetty-websocket-javadocUpgrade jetty-websocket-clientUpgrade jetty-xmlUpgrade jetty-proxyUpgrade jetty-websocket-servletUpgrade jetty-servletsUpgrade jetty-annotationsUpgrade jetty-cdiUpgrade jetty-jaasUpgrade jetty-startUpgrade jetty-websocket-serverUpgrade jetty-plusUpgrade jetty-ioUpgrade jetty-fcgiUpgrade jetty-httpUpgrade jetty-websocket-apiUpgrade jetty-jndiUpgrade jetty-http-spiUpgrade jetty-websocket-commonUpgrade jetty-javax-websocket-client-implUpgrade jetty-webappUpgrade jetty-client | Aug 28, 2025 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub