top of page
perceptive_background_267k.jpg

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gz…

Published:

4 maart 2026 om 23:00:00

Alert date:

5 maart 2026 om 11:01:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

Eclipse Jetty versions 12.0.0-12.0.31 and 12.1.0-12.0.5 contain a memory leak vulnerability in the GzipHandler class. The vulnerability occurs when processing compressed HTTP requests with Content-Encoding: gzip where the response is not compressed. The JDK Inflater allocated for decompressing the request is not properly released because the release mechanism is tied to compressed responses. When responses are uncompressed, the release mechanism fails to trigger, causing a memory leak that could lead to resource exhaustion.

Technical details

Mitigation steps:

Affected products:

Eclipse Jetty

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page