In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.
The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.
Links:
* https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
CVSS Details
- CVSS 4.0 Base Score: 7.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jetty12Upgrade jetty9 | Sep 16, 2025 | Sep 16, 2025 |
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Dec 10, 2025 | Sep 17, 2025 |
| Jenkins 2025 09 17 | — | Upgrade Jenkins to version 2.528Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.516.3 | Sep 18, 2025 | Aug 20, 2025 |
| Red Hat Jboss Eap | — | — | Oct 15, 2025 | Aug 20, 2025 |
| Suse | — | Upgrade jetty-openidUpgrade jetty-deployUpgrade jetty-antUpgrade jetty-utilUpgrade jetty-minimal-javadocUpgrade jetty-websocket-clientUpgrade jetty-javax-websocket-server-implUpgrade jetty-jmxUpgrade jetty-serverUpgrade jetty-websocket-servletUpgrade jetty-servletsUpgrade jetty-rewriteUpgrade jetty-xmlUpgrade jetty-continuationUpgrade jetty-proxyUpgrade jetty-quickstartUpgrade jetty-projectUpgrade jetty-securityUpgrade jetty-servletUpgrade jetty-jspUpgrade jetty-util-ajaxUpgrade jetty-websocket-javadocUpgrade jetty-httpUpgrade jetty-startUpgrade jetty-plusUpgrade jetty-websocket-commonUpgrade jetty-javax-websocket-client-implUpgrade jetty-cdiUpgrade jetty-websocket-serverUpgrade jetty-fcgiUpgrade jetty-ioUpgrade jetty-jaasUpgrade jetty-http-spiUpgrade jetty-annotationsUpgrade jetty-jndiUpgrade jetty-websocket-apiUpgrade jetty-webappUpgrade jetty-client | Aug 28, 2025 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub