CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-9299-c6m4-mjhc: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

highCVSS 7.5CVE-2024-7708
Impact The original report: Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state. After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer. This is particularly the case for 100-Continue, but any request where the network is slow can leak. Affected Versions - Jetty 11.0.0-11.0.22 (EOL) - Jetty 10.0.0-10.0.22 (EOL) Patched Versions - Jetty 11.0.23 - Jetty 10.0.23 Patches https://github.com/jetty/jetty.project/pull/12156 Workarounds No workarounds.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.5
Published
2026-07-22
Last updated
2026-07-22
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-9299-c6m4-mjhc

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-7708coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories