Jetty PushSessionCacheFilter can cause remote DoS attacks
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
Jetty PushSessionCacheFilter can be exploited by unauthenticated users
to launch remote DoS attacks by exhausting the server’s memory.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
Eclipse Foundation · JettyReferences
https://github.com/jetty/jetty.project/pull/10755https://github.com/jetty/jetty.project/pull/10756https://github.com/jetty/jetty.project/pull/9715https://github.com/jetty/jetty.project/pull/9716https://github.com/jetty/jetty.project/security/advisories/GHSA-r7m4-f9h5-gr79https://gitlab.eclipse.org/security/cve-assignement/-/issues/24https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html