PT-2026-23445 · Eclipse · Eclipse Jetty

·

CVE-2026-1605

·

Published

2026-03-05

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 12.0.0 through 12.0.31 Eclipse Jetty versions 12.1.0 through 12.1.5
Description Eclipse Jetty’s GzipHandler class has an issue where a memory leak occurs when processing a compressed HTTP request (Content-Encoding: gzip) without a corresponding compressed response. The JDK Inflater is allocated for decompression but is not released because the release mechanism is linked to the compressed response. Since no compressed response is sent, the release mechanism does not activate, resulting in a memory leak.
Recommendations Update Eclipse Jetty to a version later than 12.0.31. Update Eclipse Jetty to a version later than 12.1.5.

Exploit

Fix

DoS

Memory Leak

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AO61361
CLEANSTART-2026-AV84730
CLEANSTART-2026-BO52019
CLEANSTART-2026-DC73689
CLEANSTART-2026-DO09088
CLEANSTART-2026-DS86833
CLEANSTART-2026-DT81884
CLEANSTART-2026-DY69070
CLEANSTART-2026-EG39405
CLEANSTART-2026-GM79879
CLEANSTART-2026-GN46454
CLEANSTART-2026-GQ14179
CLEANSTART-2026-GX44743
CLEANSTART-2026-HQ78610
CLEANSTART-2026-IA43044
CLEANSTART-2026-KB76878
CLEANSTART-2026-RG24361
CLEANSTART-2026-RM01950
CLEANSTART-2026-SR31778
CLEANSTART-2026-TK07726
CLEANSTART-2026-VH00240
CLEANSTART-2026-VN28553
CLEANSTART-2026-VP53607
CLEANSTART-2026-WT54034
CLEANSTART-2026-YX54699
CVE-2026-1605
GHSA-XXH7-FCF3-RJ7F
RHSA-2026:25125

Affected Products

Eclipse Jetty