CVE-2025-1948
Eclipse Jetty HTTP clients can increase memory allocation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE.
The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
A flaw was found in Eclipse Jetty. This vulnerability allows denial of service attack via an HTTP/2 client specifying a very large value for the SETTINGS_MAX_HEADER_LIST_SIZE parameter.
In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
Red Hat build of Apache Camel 4.10.3 for Spring Boot release and security update is now available.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-03-04 CVE Reserved
- 2025-05-08 CVE Published
- 2025-05-08 CVE Updated
- 2025-06-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/jetty/jetty.project/security/advisories/GHSA-889j-63jv-qhr8 | ||
https://gitlab.eclipse.org/security/cve-assignement/-/issues/56 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2025-1948 | 2025-05-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2365137 | 2025-05-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Foundation Search vendor "Eclipse Foundation" | Jetty Search vendor "Eclipse Foundation" for product "Jetty" | >= 12.0.0 <= 12.0.16 Search vendor "Eclipse Foundation" for product "Jetty" and version " >= 12.0.0 <= 12.0.16" | en |
Affected
|