PT-2026-86673 · Eclipse Foundation+1 · Eclipse Jetty+1

·

CVE-2026-19204

·

Published

2026-09-07

·

Updated

2026-09-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.
This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19204
GHSA-85FQ-FC5F-7J7G

Affected Products

Eclipse Jetty
Jetty.Project