CVE-2025-5115
published 2025-08-20CVE-2025-5115: In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.57%
72.6th percentile
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.
Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.
The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time.
The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame.
Links:
* https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty12 | < jetty12 12.0.17-3.1 (forky) | jetty12 12.0.17-3.1 (forky) |
| debian | jetty9 | < jetty12 12.0.17-3.1 (forky) | jetty12 12.0.17-3.1 (forky) |
| eclipse | jetty | — | — |
| eclipse | jetty | 10.0.0 – 10.0.25 | — |
| eclipse | jetty | 11.0.0 – 11.0.25 | — |
| eclipse | jetty | 12.0.0 – 12.0.21 | — |
| eclipse | jetty | 9.3.0 – 9.4.57 | — |
| eclipse_jetty | eclipse_jetty | >=10.0.0 – <=10.0.25 | — |
| eclipse_jetty | eclipse_jetty | >=11.0.0 – <=11.0.25 | — |
| eclipse_jetty | eclipse_jetty | >=12.0.0 – <=12.0.21 | — |
| eclipse_jetty | eclipse_jetty | >=12.1.0.alpha0 – <=12.1.0.alpha2 | — |
| eclipse_jetty | eclipse_jetty | >=9.3.0 – <=9.4.57 | — |
| jenkins | credentials_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| msrc | azl3_ansible_2.15.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ansible_2.17.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ansible_2.14.11-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_ansible_2.14.12-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.7HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
vendor_oracle7.5HIGH
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Core (Eclipse Jetty) — CVE-2025-5115
vendor_oracle·2026-01-15·CVSS 4.9
CVE-2025-5115 [HIGH] Oracle Oracle Communications Risk Matrix: Core (Eclipse Jetty) — CVE-2025-5115
Oracle Oracle Communications Risk Matrix: Core (Eclipse Jetty) vulnerability
CVE: CVE-2025-5115
CVSS: 4.9
Protocol: HTTP/2
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Eclipse Jetty) — CVE-2025-5115
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2025-5115 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Eclipse Jetty) — CVE-2025-5115
Oracle Oracle Communications Applications Risk Matrix: Security (Eclipse Jetty) vulnerability
CVE: CVE-2025-5115
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Jenkins
Jenkins Security Advisory 2025-09-17
vendor_jenkins·2025-09-17·CVSS 7.7
CVE-2025-5115 [HIGH] Jenkins Security Advisory 2025-09-17
Title: Jenkins Security Advisory 2025-09-17
Jenkins Security Advisory 2025-09-17
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Descriptions
HTTP/2 denial of service vulnerability in bundled Jetty
SECURITY-3618
/
CVE-2025-5115
Severity (CVSS):
High
Description:
Jenkins bundles Winstone-Jet
Red Hat
jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames
vendor_redhat·2025-08-20·CVSS 7.7
CVE-2025-5115 [HIGH] CWE-400 jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames
jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory.
For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal.
Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame.
The client can now open another stream and send another bad WINDOW_UPDAT
Red Hat
upstream:
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] upstream:
upstream:
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
A flaw was found in multiple implementations of HTTP/2 where malformed cli
Debian
CVE-2025-5115: jetty12 - In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.a...
vendor_debian·2025·CVSS 7.7
CVE-2025-5115 [HIGH] CVE-2025-5115: jetty12 - In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.a...
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, y
Microsoft
Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
vendor_msrc·2023-12-12·CVSS 6.3
CVE-2023-5115 [MEDIUM] CWE-36 Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Re
GHSA
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
ghsa·2025-08-20
CVE-2025-5115 [HIGH] CWE-400 Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
## Technical Details
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”
### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.
### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame).
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1.
OSV
CVE-2025-5115: In Eclipse Jetty, versions <=9
osv·2025-08-20·CVSS 7.7
CVE-2025-5115 [HIGH] CVE-2025-5115: In Eclipse Jetty, versions <=9
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, y
OSV
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
osv·2025-08-20
CVE-2025-5115 [HIGH] Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
## Technical Details
Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”
### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.
### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame).
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1.
No detection rules found.
No public exploits indexed.
https://github.com/jetty/jetty.project/pull/13449https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.26https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.26https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.0https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.58.v20250814https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4hhttp://www.openwall.com/lists/oss-security/2025/08/20/4http://www.openwall.com/lists/oss-security/2025/09/17/1https://lists.debian.org/debian-lts-announce/2025/09/msg00014.htmlhttps://www.kb.cert.org/vuls/id/767506
2025-08-20
Published