CVE-2024-13009
published 2025-05-08CVE-2024-13009: In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result…
PriorityP343high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.45%
36.6th percentile
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request
body. This can result in corrupted and/or inadvertent sharing of data between requests.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty12 | < jetty9 9.4.57-0+deb12u1 (bookworm) | jetty9 9.4.57-0+deb12u1 (bookworm) |
| debian | jetty9 | < jetty9 9.4.57-0+deb12u1 (bookworm) | jetty9 9.4.57-0+deb12u1 (bookworm) |
| eclipse | jetty | >= 9.4.0 < 9.4.57 | 9.4.57 |
| eclipse_foundation | jetty | 9.4.0 – 9.4.56 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
osv7.2HIGH
vendor_debian7.2LOW
vendor_oracle7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
osv·2025-05-08
CVE-2024-13009 [HIGH] **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
OSV
CVE-2024-13009: In Eclipse Jetty versions 9
osv·2025-05-08·CVSS 7.2
CVE-2024-13009 [HIGH] CVE-2024-13009: In Eclipse Jetty versions 9
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
GHSA
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
ghsa·2025-05-08
CVE-2024-13009 [HIGH] CWE-404 **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Gateway (Eclipse Jetty) — CVE-2024-13009
vendor_oracle·2026-01-15·CVSS 7.2
CVE-2024-13009 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Gateway (Eclipse Jetty) — CVE-2024-13009
Oracle Oracle Enterprise Manager Risk Matrix: Gateway (Eclipse Jetty) vulnerability
CVE: CVE-2024-13009
CVSS: 7.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Eclipse Jetty) — CVE-2024-13009
vendor_oracle·2025-10-15·CVSS 7.2
CVE-2024-13009 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Eclipse Jetty) — CVE-2024-13009
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (Eclipse Jetty) vulnerability
CVE: CVE-2024-13009
CVSS: 7.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
jetty-server: Jetty: Gzip Request Body Buffer Corruption
vendor_redhat·2025-05-08·CVSS 7.2
CVE-2024-13009 [HIGH] CWE-404 jetty-server: Jetty: Gzip Request Body Buffer Corruption
jetty-server: Jetty: Gzip Request Body Buffer Corruption
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request
body. This can result in corrupted and/or inadvertent sharing of data between requests.
A flaw was found in Eclipse Jetty. This vulnerability allows corrupted and inadvertent data sharing between requests via a gzip error when inflating a request body. If the request body is malformed, the gzip decompression process can fail, resulting in the application inadvertently using data from a previous request when processing the current one.
Statement: This vulnerability is rated as an IMPORTANT severity because a buffer management vulnerability exists within the GzipHandler's buffer release mechanism
Debian
CVE-2024-13009: jetty12 - In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released w...
vendor_debian·2024·CVSS 7.2
CVE-2024-13009 [HIGH] CVE-2024-13009: jetty12 - In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released w...
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-13009 jetty: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
bugzilla·2025-05-15·CVSS 7.2
CVE-2024-13009 [HIGH] CVE-2024-13009 jetty: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
CVE-2024-13009 jetty: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365135
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Mai
Bugzilla
CVE-2024-13009 python-avro: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
bugzilla·2025-05-15·CVSS 7.2
CVE-2024-13009 [HIGH] CVE-2024-13009 python-avro: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
CVE-2024-13009 python-avro: Jetty: Gzip Request Body Buffer Corruption [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2365135
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Looking to get this fixed asap, thank you for the heads up!
---
Not sure how this slipped though the cracks, but this does not affect this package, as this does not include the jetty server.
Bugzilla
CVE-2024-13009 jetty-server: Jetty: Gzip Request Body Buffer Corruption
bugzilla·2025-05-08·CVSS 7.2
CVE-2024-13009 [HIGH] CVE-2024-13009 jetty-server: Jetty: Gzip Request Body Buffer Corruption
CVE-2024-13009 jetty-server: Jetty: Gzip Request Body Buffer Corruption
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request
body. This can result in corrupted and/or inadvertent sharing of data between requests.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel 4.10.3 for Spring Boot 3.4.7
Via RHSA-2025:9697 https://access.redhat.com/errata/RHSA-2025:9697
---
This issue has been addressed in the following products:
Streams for Apache Kafka 2.9.1
Via RHSA-2025:9922 https://access.redhat.com/errata/RHSA-2025:9922
---
This issue has been addressed in the following products:
Streams for Apache Kafka 3.0.0
Via RHSA-2025:12511 https://access.redhat.c
2025-05-08
Published