PT-2023-25586 · Eclipse+6 · Eclipse Jetty+8

Jmcc0Nn3Ll

+3

·

Published

2023-10-10

·

Updated

2025-09-29

·

CVE-2023-36478

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.0.0 through 9.4.52 Eclipse Jetty versions 10.0.0 through 10.0.15 Eclipse Jetty versions 11.0.0 through 11.0.15
Description The issue is caused by an integer overflow in MetaDataBuilder.checkSize, allowing HTTP/2 HPACK header values to exceed their size limit. When the length is very large and huffman is true, the multiplication by 4 will overflow, and the length will become negative. This can lead to a very large buffer allocation later on when the user-entered size is multiplied by 2. Users of HTTP/2 can be impacted by a remote denial of service attack.
Recommendations For Eclipse Jetty versions 9.0.0 through 9.4.52, upgrade to version 9.4.53 or later. For Eclipse Jetty versions 10.0.0 through 10.0.15, upgrade to version 10.0.16 or later. For Eclipse Jetty versions 11.0.0 through 11.0.15, upgrade to version 11.0.16 or later.

Exploit

Fix

DoS

Integer Overflow

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-16002
ALT-PU-2024-16022
ALT-PU-2024-16072
BIT-JENKINS-2023-36478
CVE-2023-36478
DLA-3641-1
DSA-5540-1
GHSA-WGH7-54F2-X98R
OPENSUSE-SU-2023_4210-1
OPENSUSE-SU-2024:13329-1
SUSE-SU-2023:4210-1

Affected Products

Alt Linux
Astra Linux
Bamboo
Bitbucket
Confluence
Eclipse Jetty
Jenkins
Red Os
Suse