CVE-2026-19204
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.
| CWE | CWE-770 CWE-789 |
| Vendor | eclipse foundation |
| Product | eclipse jetty |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse jetty
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse jetty are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Jetty
12.1.0 โค 12.1.11 12.0.0 โค 12.0.37 11.0.0 โค 11.0.31 10.0.0 โค 10.0.31
References
Credits
๐ Arthur Chan ๐ David Korczynski ๐ Adam Korcz