maven package report

Is org.eclipse.jetty:jetty-server safe?

27 known vulnerabilities, worst severity CRITICAL.

cvss
9.0

how bad it is if exploited, out of 10

epss
11.1%

chance of exploitation in the next 30 days

xyz score
4.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-x3rh-m7vp-35f2, the advisory selected below

// advisories

GHSA-x3rh-m7vp-35f2

CRITICALCVE-2019-17638

In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use

Affected
>= 9.4.27, <= 9.4.30.v20200610
Fixed in
9.4.30.v20200611
Weakness
CWE-672
Published
2020-08-05
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:46 UTC. The most recent advisory here was published 2026-07-22. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.eclipse.jetty:jetty-server safe? maven package security report | CyberXYZ