4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.eclipse.jetty.http2:jetty-http2-common is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2023-44487
HTTP/2 Stream Cancellation Attack
HIGH 7.5
CVE-2024-22201
Connection leaking on idle timeout when TCP congested
HIGH 7.5
CVE-2025-1948
Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
HIGH 7.5
CVE-2025-5115
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes