Allocation of Resources Without Limits or Throttling Affecting org.eclipse.jetty.http2:http2-server package, versions [,9.4.58.v20250814)[10.0.0-alpha0,10.0.26)[11.0.0-alpha0,11.0.26)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGECLIPSEJETTYHTTP2-12047640
  • published21 Aug 2025
  • disclosed20 Aug 2025
  • creditUnknownAnat Bremler-Barr, Gal Bar Nahum, Yaniv Harel

Introduced: 20 Aug 2025

NewCVE-2025-5115  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade org.eclipse.jetty.http2:http2-server to version 9.4.58.v20250814, 10.0.26, 11.0.26 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via malformed HTTP/2 control frames that manipulate the RST_STREAM process. An attacker can exhaust server resources and disrupt service availability by rapidly sending specially crafted frames that cause the server to reset streams and miscount active connections.

CVSS Base Scores

version 4.0
version 3.1