GHSA-6x9x-8qw9-9pp6 · Severity: critical · Ecosystem: maven — Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
Conclusion & alert: CVE-2017-7658 is rated High Risk (67.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 5.48%, 90th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-04 | 8.61% | 5.48% | -3.13% |
| 2 | 2026-04-24 | 8.04% | 8.61% | +0.57% |
| 3 | 2026-03-18 | — | 8.04% | — |
Full EPSS history (53 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-6x9x-8qw9-9pp6 · Severity: critical · Ecosystem: maven — Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2017-7658 low priority: Debian including 1 source packages (jetty9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-7658 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2017-7658 |
ubuntu
|
low | CVE-2017-7658 low priority: Ubuntu including 2 source packages (jetty8, jetty9), 40 status rows across 20 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 18, not-affected 15, ignored 3, needed 3, released 1. | https://ubuntu.com/security/CVE-2017-7658 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eclipse | jetty | <= 9.2.26 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 9.3.0, < 9.3.24 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 9.4.0, < 9.4.11 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| oracle | rest_data_services | 11.2.0.4 | cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:* |
| oracle | rest_data_services | 12.1.0.2 | cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:* |
| oracle | rest_data_services | 12.2.0.1 | cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:* |
| oracle | rest_data_services | 18c | cpe:2.3:a:oracle:rest_data_services:18c:*:*:*:-:*:*:* |
| oracle | retail_xstore_payment | 3.3 | cpe:2.3:a:oracle:retail_xstore_payment:3.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 7.1 | cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 15.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0:*:*:*:*:*:*:* |
| hp | xp_p9000_command_view | >= 8.4.0-00, <= 8.6.2-00 | cpe:2.3:a:hp:xp_p9000_command_view:*:*:*:*:advanced:*:*:* |
| netapp | e-series_santricity_management | — | cpe:2.3:a:netapp:e-series_santricity_management:-:*:*:*:*:*:*:* |
| netapp | e-series_santricity_os_controller | >= 11.0, <= 11.50.1 | cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* |
| netapp | e-series_santricity_web_services | — | cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:*:*:* |
| netapp | hci_management_node | — | cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:* |
| netapp | hci_storage_node | — | cpe:2.3:a:netapp:hci_storage_node:-:*:*:*:*:*:*:* |
| netapp | oncommand_system_manager | >= 3.0, <= 3.1.3 | cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* |
| netapp | oncommand_unified_manager_for_7-mode | — | cpe:2.3:a:netapp:oncommand_unified_manager_for_7-mode:-:*:*:*:*:*:*:* |
| netapp | santricity_cloud_connector | — | cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:* |
| netapp | snap_creator_framework | — | cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* |
| netapp | snapcenter | — | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |
| netapp | snapmanager | — | cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:* |
| netapp | snapmanager | — | cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:* |
| netapp | solidfire | — | cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:* |
| netapp | storage_services_connector | — | cpe:2.3:a:netapp:storage_services_connector:-:*:*:*:*:*:*:* |