Dependency scanning
Check whether org.eclipse.jetty:jetty-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-6790
Eclipse Jetty: HTTP Authority/Host mismatch
CVE-2026-10051
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
CVE-2026-1605
The Eclipse Jetty Server Artifact has a Gzip request memory leak
CVE-2024-13009
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
CVE-2024-8184
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
CVE-2023-26049
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-26048
OutOfMemoryError for large multipart without filename in Eclipse Jetty
CVE-2024-7708
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
CVE-2021-34428
SessionListener can prevent a session from being invalidated breaking logout
CVE-2022-2191
Jetty SslConnection does not release pooled ByteBuffers in case of errors
CVE-2021-28165
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
CVE-2020-27218
Buffer not correctly recycled in Gzip Request inflation
CVE-2020-27223
DOS vulnerability for Quoted Quality CSV headers
CVE-2018-12545
Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server
CVE-2011-4461
Improper Input Validation in Jetty
CVE-2019-17638
Operation on a Resource after Expiration or Release in Jetty Server
CVE-2019-10247
Installation information leak in Eclipse Jetty
CVE-2018-12538
Access and integrity issue within Eclipse Jetty
CVE-2017-7657
Critical severity vulnerability that affects org.eclipse.jetty:jetty-server
CVE-2017-9735
Jetty vulnerable to exposure of sensitive information due to observable discrepancy
CVE-2016-4800
Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
CVE-2015-2080
Jetty vulnerable to exposure of sensitive information to unauthenticated remote users
CVE-2017-7656
Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)
CVE-2019-10241
Cross-site Scripting in Eclipse Jetty
CVE-2018-12536
Eclipse Jetty Server generates error message containing sensitive information
CVE-2017-7658
Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
CVE-2019-17632
Unescaped exception messages in error responses in Jetty
CVE-2019-10246
Information Exposure vulnerability in Eclipse Jetty
CVE-2006-6969
Jetty Uses Predictable Session Identifiers
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes