Description
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
Scores
CVSS v3
7.5
EPSS
0.0066
EPSS Percentile
71.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-664
CWE-404
Status
published
Products (2)
eclipse/jetty
10.0.0 - 10.0.9
org.eclipse.jetty/jetty-server
10.0.0 - 10.0.10Maven
Published
Jul 07, 2022
Tracked Since
Feb 18, 2026