PT-2025-20401 · Eclipse+4 · Eclipse Jetty+4

Published

2024-10-14

·

Updated

2026-05-18

·

CVE-2024-13009

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.4.0 through 9.4.56
Description A buffer can be incorrectly released when Eclipse Jetty encounters a gzip error while inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Recommendations For Eclipse Jetty versions 9.4.0 through 9.4.56, update to a version that fixes the buffer release issue when confronted with gzip errors during request body inflation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-10117
BDU:2025-03454
BDU:2025-08601
BDU:2025-08602
CLEANSTART-2026-DD05788
CLEANSTART-2026-GH89210
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-LO22603
CLEANSTART-2026-RN56220
CLEANSTART-2026-SQ91016
CLEANSTART-2026-VH41554
CLEANSTART-2026-WK99982
CVE-2024-13009
DLA-4106-1
DLA-4106-2
DSA-5894-1
GHSA-Q4RV-GQ96-W7C5
OPENSUSE-SU-2025:15160-1
OPENSUSE-SU-2025_01738-1
RHSA-2025:15643
SUSE-SU-2025:01738-1
SUSE-SU-2025_01738-1

Affected Products

Bamboo
Debian
Eclipse Jetty
Red Os
Suse