๐Ÿ” CVE Alert

CVE-2026-19204

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

CWE CWE-770 CWE-789
Vendor eclipse foundation
Product eclipse jetty
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse jetty

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse jetty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Jetty
12.1.0 โ‰ค 12.1.11 12.0.0 โ‰ค 12.0.37 11.0.0 โ‰ค 11.0.31 10.0.0 โ‰ค 10.0.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jetty/jetty.project/security/advisories/GHSA-85fq-fc5f-7j7g

Credits

๐Ÿ” Arthur Chan ๐Ÿ” David Korczynski ๐Ÿ” Adam Korcz