CVE-2025-1948

Aliases:GHSA-889j-63jv-qhr8DEBIAN-CVE-2025-1948CGA-5559-3cch-qhfwCGA-f984-cp62-h7p8CGA-hrcq-cqhh-6mmgCGA-wh6j-9g8h-2hj9
Advisory lineage Upstream: 0 Downstream: 9
Analyzed
Published: 08 May 2025, 17:48
Last modified:08 May 2025, 18:31

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.75% LOW
1% probability +0.62%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 May 2025, 17:48
Published
Vulnerability first disclosed
08 May 2025, 18:31
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.75% Percentile: 53%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguardneo4j-5.26

    < 5.26.6-r1

  • chainguardneo4j-5.26-docker-publish

    < 5.26.6-r1

  • debianjetty12

    < 12.0.17-1 | < 12.0.17-1

  • eclipse foundationjetty

    ≥ 12.0.0, ≤ 12.0.16

  • eclipsejetty

    ≥ 12.0.0, < 12.0.17

  • org.eclipse.jetty.http2jetty-http2-common

    ≥ 12.0.0, < 12.0.17

References (8)