PT-2026-23445 · Eclipse · Eclipse Jetty

Gleb Sizov

·

Published

2026-03-05

·

Updated

2026-05-31

·

CVE-2026-1605

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 12.0.0 through 12.0.31 Eclipse Jetty versions 12.1.0 through 12.1.5
Description Eclipse Jetty’s GzipHandler class has an issue where a memory leak occurs when processing a compressed HTTP request (Content-Encoding: gzip) without a corresponding compressed response. The JDK Inflater is allocated for decompression but is not released because the release mechanism is linked to the compressed response. Since no compressed response is sent, the release mechanism does not activate, resulting in a memory leak.
Recommendations Update Eclipse Jetty to a version later than 12.0.31. Update Eclipse Jetty to a version later than 12.1.5.

Fix

Memory Leak

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AO61361
CLEANSTART-2026-AV84730
CLEANSTART-2026-DC73689
CLEANSTART-2026-DO09088
CLEANSTART-2026-DS86833
CLEANSTART-2026-DY69070
CLEANSTART-2026-GM79879
CLEANSTART-2026-GN46454
CLEANSTART-2026-GQ14179
CLEANSTART-2026-HQ78610
CLEANSTART-2026-IA43044
CLEANSTART-2026-KB76878
CLEANSTART-2026-RG24361
CLEANSTART-2026-RM01950
CLEANSTART-2026-SR31778
CLEANSTART-2026-TK07726
CLEANSTART-2026-VN28553
CVE-2026-1605
GHSA-XXH7-FCF3-RJ7F

Affected Products

Eclipse Jetty