In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
History

Thu, 31 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse jetty
CPEs cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Vendors & Products Eclipse
Eclipse jetty

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00057}

epss

{'score': 0.0006}


Wed, 02 Jul 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ocp Tools
CPEs cpe:/a:redhat:ocp_tools:4.12::el8
cpe:/a:redhat:ocp_tools:4.13::el8
cpe:/a:redhat:ocp_tools:4.14::el8
cpe:/a:redhat:ocp_tools:4.15::el8
cpe:/a:redhat:ocp_tools:4.16::el9
cpe:/a:redhat:ocp_tools:4.17::el9
cpe:/a:redhat:ocp_tools:4.18::el9
Vendors & Products Redhat ocp Tools

Fri, 16 May 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat apache Camel Spring Boot
CPEs cpe:/a:redhat:apache_camel_spring_boot:4.10.3
Vendors & Products Redhat
Redhat apache Camel Spring Boot

Sat, 10 May 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 08 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 May 2025 18:00:00 +0000

Type Values Removed Values Added
Description In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
Title Eclipse Jetty HTTP clients can increase memory allocation
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2025-05-08T17:48:40.831Z

Updated: 2025-05-08T18:31:44.196Z

Reserved: 2025-03-04T13:55:56.722Z

Link: CVE-2025-1948

cve-icon Vulnrichment

Updated: 2025-05-08T18:31:35.426Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-08T18:15:41.990

Modified: 2025-07-31T16:28:26.603

Link: CVE-2025-1948

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-08T17:48:40Z

Links: CVE-2025-1948 - Bugzilla