CVE-2026-1605
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.5epss 0.6%
probabilidade de exploração
0.6%top 53% das CVEs
exploração observada
nãonenhuma fonte reporta
In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.
This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.
In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
Eclipse Foundation · Eclipse JettyReferências
https://access.redhat.com/errata/RHSA-2026:21772https://access.redhat.com/errata/RHSA-2026:25089https://access.redhat.com/errata/RHSA-2026:25125https://access.redhat.com/errata/RHSA-2026:25126https://access.redhat.com/errata/RHSA-2026:8509https://access.redhat.com/security/cve/CVE-2026-1605https://bugzilla.redhat.com/show_bug.cgi?id=2444815https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7fhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1605.json