GHSA-84q7-p226-4x5w · Severity: high · Ecosystem: maven — Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.
Conclusion & alert: CVE-2017-7656 is rated Moderate Risk (60.6/100): CVSS High severity, with high exploitation likelihood (EPSS 6.41%, 93th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 8.32% | 6.41% | -1.91% |
| 2 | 2026-06-10 | 8.53% | 8.32% | -0.21% |
| 3 | 2026-05-28 | — | 8.53% | — |
Full EPSS history (55 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-84q7-p226-4x5w · Severity: high · Ecosystem: maven — Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2017-7656 low priority: Debian including 1 source packages (jetty9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-7656 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2017-7656 |
ubuntu
|
medium | CVE-2017-7656 medium priority: Ubuntu including 2 source packages (jetty8, jetty9), 40 status rows across 20 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 18, not-affected 15, ignored 3, needed 2, released 2. | https://ubuntu.com/security/CVE-2017-7656 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eclipse | jetty | <= 9.2.26 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 9.3.0, < 9.3.24 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 9.4.0, < 9.4.11 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |