VendorsEclipsejettyall versions
Vulnerabilities

Eclipse Jetty

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2019-10246
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.
Published 2019-04-22 · Modified
5.3EPSS 0.041
CVE-2023-26048
OutOfMemoryError for large multipart without filename in Eclipse Jetty
Published 2023-04-18 · Modified
5.3EPSS 0.033
CVE-2023-26049
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Published 2023-04-18 · Modified
5.3EPSS 0.013
CVE-2023-40167
Jetty accepts "+" prefixed value in Content-Length
Published 2023-09-15 · Modified
5.3EPSS 0.013
CVE-2024-6763
Jetty URI parsing of invalid authority
Published 2024-10-14 · Analyzed
5.3EPSS 0.010
CVE-2026-8384
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.
Published 2026-07-14 · Analyzed
5.3EPSS 0.003
CVE-2026-6790
In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112). This mismatch can cause a number of problems that may be classified as vulnerabilities such as: * URI constructions (for example, for redirects -- this is typical for login pages) * Virtual host selection * Reverse proxying * Misleading logs * Etc. Given that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.
Published 2026-07-14 · Analyzed
5.3EPSS 0.003
CVE-2023-41900
Jetty's OpenId Revoked authentication allows one request
Published 2023-09-15 · Modified
4.3EPSS 0.009
CVE-2021-28163
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
Published 2021-04-01 · Modified
4.0EPSS 0.042
CVE-2022-2047
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
Published 2022-07-07 · Modified
4.0EPSS 0.013
CVE-2021-34428
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Published 2021-06-22 · Modified
3.6EPSS 0.010
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
Published 2023-09-15 · Analyzed
3.5EPSS 0.012
← Prev2 / 2