CVE-2021-28165

HIGH

Eclipse Jetty 7.2.2-9.4.38, 10.0.0.alpha0-10.0.1, 11.0.0.alpha0-11.0.1 - Denial of Service via Invalid TLS Frame

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-28165. PoCs published by uthrasri.

AI-analyzed exploit summary The repository contains source code files from the Eclipse Jetty server, specifically focusing on connection handling and protocol management. It appears to be a snapshot of the vulnerable codebase for CVE-2021-28165, which involves a security issue in Jetty's connection handling, but lacks explicit exploit code or technical analysis.

Description

In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

Exploits (1)

nomisec WRITEUP
by uthrasri · poc
https://github.com/uthrasri/CVE-2021-28165

The repository contains source code files from the Eclipse Jetty server, specifically focusing on connection handling and protocol management. It appears to be a snapshot of the vulnerable codebase for CVE-2021-28165, which involves a security issue in Jetty's connection handling, but lacks explicit exploit code or technical analysis.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Eclipse Jetty Server (version not explicitly specified)
No auth needed
Prerequisites: Access to a vulnerable Jetty server instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (107)

Core 107
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/04/20/3
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Mailing List, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210611-0006/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4949
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Not Applicable, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 7.5
EPSS 0.1358
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-755 CWE-551 CWE-400
Status published
Products (23)
eclipse/jetty 7.2.2 - 9.4.39
jenkins/jenkins < 2.277.3
jenkins/jenkins < 2.286
netapp/cloud_manager < 3.9.8
netapp/e-series_performance_analyzer < 3.0
netapp/e-series_santricity_os_controller 11.0.0 - 11.70.1
netapp/e-series_santricity_storage < 1.10
netapp/e-series_santricity_web_services < 5.1
netapp/ontap_tools < 9.10
netapp/santricity_cloud_connector
... and 13 more
Published Apr 01, 2021
Tracked Since Feb 18, 2026