cbcvebase.
CVE-2025-11143
published 2026-03-05

CVE-2025-11143: The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.16%
5.5th percentile
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianjetty12< jetty12 12.0.32-1 (forky)jetty12 12.0.32-1 (forky)
debianjetty9< jetty12 12.0.32-1 (forky)jetty12 12.0.32-1 (forky)
eclipsejetty10.0.0 – 10.0.26
eclipsejetty11.0.0 – 11.0.26
eclipsejetty>= 12.0.0 < 12.0.3112.0.31
eclipsejetty>= 12.1.0 < 12.1.512.1.5
eclipsejetty9.4.0 – 9.4.58
eclipse_foundationeclipse_jetty10.0.0 – 10.0.26
eclipse_foundationeclipse_jetty11.0.0 – 11.0.26
eclipse_foundationeclipse_jetty12.0.0 – 12.0.30
eclipse_foundationeclipse_jetty12.1.0 – 12.1.4
eclipse_foundationeclipse_jetty9.4.0 – 9.4.58

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.