In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.
The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.
Links:
* https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
CVSS Details
- CVSS 4.0 Base Score: 7.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jetty12Upgrade jetty9 | Sep 16, 2025 | Sep 16, 2025 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Dec 10, 2025 | Sep 17, 2025 |
| Jenkins 2025 09 17 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.516.3Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.528 | Sep 18, 2025 | Aug 20, 2025 |
| Red Hat Jboss Eap | — | — | Oct 15, 2025 | Aug 20, 2025 |
| Suse | — | Upgrade jetty-proxyUpgrade jetty-quickstartUpgrade jetty-jmxUpgrade jetty-rewriteUpgrade jetty-securityUpgrade jetty-javax-websocket-server-implUpgrade jetty-xmlUpgrade jetty-antUpgrade jetty-openidUpgrade jetty-websocket-servletUpgrade jetty-utilUpgrade jetty-minimal-javadocUpgrade jetty-deployUpgrade jetty-servletsUpgrade jetty-util-ajaxUpgrade jetty-serverUpgrade jetty-websocket-clientUpgrade jetty-projectUpgrade jetty-websocket-javadocUpgrade jetty-jspUpgrade jetty-servletUpgrade jetty-continuationUpgrade jetty-clientUpgrade jetty-javax-websocket-client-implUpgrade jetty-websocket-commonUpgrade jetty-plusUpgrade jetty-cdiUpgrade jetty-websocket-apiUpgrade jetty-jndiUpgrade jetty-websocket-serverUpgrade jetty-jaasUpgrade jetty-http-spiUpgrade jetty-annotationsUpgrade jetty-fcgiUpgrade jetty-ioUpgrade jetty-webappUpgrade jetty-startUpgrade jetty-http | Aug 28, 2025 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub