GHSA-mmxm-8w33-wc4h · 深刻度: high · エコシステム: maven — Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time. The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame. Links: * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h
総合評価: CVE-2025-5115 は中リスク(57/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 1.57%、72 パーセンタイル) 推奨対応: 影響資産を整理し、修補計画に組み込んでください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.57% | 1.57% | +0.99% |
| 2 | 2026-06-06 | 0.47% | 0.57% | +0.10% |
| 3 | 2026-05-13 | — | 0.47% | — |
EPSS の全履歴 (全 5 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-mmxm-8w33-wc4h · 深刻度: high · エコシステム: maven — Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-5115 not yet assigned priority: Debian including 2 source packages (jetty12, jetty9), 8 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 8. | https://security-tracker.debian.org/tracker/CVE-2025-5115 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-5115 |
suse
|
high | CVE-2025-5115 severity important: SUSE including 68 source package names (jetty-annotations-9.4.58-1.1, jetty-annotations-9.4.58-150200.3.34.1, …), 197 product×package rows across 21 product lines (Image server-image, SUSE Enterprise Storage 7.1, … (21 product lines)): Fixed 197. | https://www.suse.com/security/cve/CVE-2025-5115/ |
ubuntu
|
medium | CVE-2025-5115 medium priority: Ubuntu including 2 source packages (jetty, jetty9), 15 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): needs-triage 10, DNE 4, ignored 1. | https://ubuntu.com/security/CVE-2025-5115 |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| eclipse | jetty | >= 9.3.0, <= 9.4.57 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 10.0.0, <= 10.0.25 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 11.0.0, <= 11.0.25 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 12.0.0, <= 12.0.21 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | 12.1.0 | cpe:2.3:a:eclipse:jetty:12.1.0:alpha0:*:*:*:*:*:* |
| eclipse | jetty | 12.1.0 | cpe:2.3:a:eclipse:jetty:12.1.0:alpha1:*:*:*:*:*:* |
| eclipse | jetty | 12.1.0 | cpe:2.3:a:eclipse:jetty:12.1.0:alpha2:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| https://github.com/jetty/jetty.project/pull/13449 | Issue Tracking |
| https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.26 | Release Notes |
| https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.26 | Release Notes |
| https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.25 | Release Notes |
| https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.0 | Release Notes |
| https://github.com/jetty/jetty.project/releases/tag/jetty-9.4.58.v20250814 | Release Notes |
| https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4h | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/20/4 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/09/17/1 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/09/msg00014.html | Issue Tracking Mailing List |
| https://www.kb.cert.org/vuls/id/767506 | Third Party Advisory |