<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:47:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05507</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05507</link>
      <description>bdu:2022-05507</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05507</guid>
    </item>
    <item>
      <title>BIT-jenkins-2021-28165</title>
      <link>https://cve.radiocsirt.org/vuln/bit-jenkins-2021-28165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: jenkins&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-jenkins-2021-28165</guid>
    </item>
    <item>
      <title>certfr-2021-avi-912 — De multiples vulnérabilités ont été découvertes dans IBM Qradar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-912</link>
      <description>certfr-2021-avi-912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-912</guid>
    </item>
    <item>
      <title>cnvd-2021-25683</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-25683</link>
      <description>cnvd-2021-25683</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-25683</guid>
    </item>
    <item>
      <title>EUVD-2026-251100</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-251100</link>
      <description>EUVD-2026-251100</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-251100</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28165</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28165</link>
      <description>&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28165</guid>
    </item>
    <item>
      <title>GHSA-26vr-8j45-3r4w — Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-26vr-8j45-3r4w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-server&lt;/p&gt;
&lt;p&gt;### Impact
When using SSL/TLS with Jetty, either with HTTP/1.1, HTTP/2, or WebSocket, the server may receive an invalid large (greater than 17408) TLS frame that is incorrectly handled, causing CPU resources to eventually reach 100% usage.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;The problem can be worked around by compiling the following class:
```java
package org.eclipse.jetty.server.ssl.fix6072;&lt;/p&gt;
&lt;p&gt;import java.nio.ByteBuffer;
import javax.net.ssl.SSLEngine;
import javax.net.ssl.SSLEngineResult;
import javax.net.ssl.SSLException;
import javax.net.ssl.SSLHandshakeException;&lt;/p&gt;
&lt;p&gt;import org.eclipse.jetty.io.EndPoint;
import org.eclipse.jetty.io.ssl.SslConnection;
import org.eclipse.jetty.server.Connector;
import org.eclipse.jetty.server.SslConnectionFactory;
import org.eclipse.jetty.util.BufferUtil;
import org.eclipse.jetty.util.annotation.Name;
import org.eclipse.jetty.util.ssl.SslContextFactory;&lt;/p&gt;
&lt;p&gt;public class SpaceCheckingSslConnectionFactory extends SslConnectionFactory
{
    public SpaceCheckingSslConnectionFactory(@Name(&amp;#34;sslContextFactory&amp;#34;) SslContextFactory factory, @Name(&amp;#34;next&amp;#34;) String nextProtocol)
    {
        super(factory, nextProtocol);
    }&lt;/p&gt;
&lt;p&gt;@Override
    protected SslConnection newSslConnection(Connector connector, EndPoint endPoint, SSLEngine engine)
    {
        return new SslConnection(connector.getByteBufferPool(), connector.getExecutor(), endPoint, engine, isDirectBuffersForEncryption(), isDirectBuffersForDecryption())
        {
            @Override
            protected SSLEn…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-server&lt;/p&gt;
&lt;p&gt;### Impact
When using SSL/TLS with Jetty, either with HTTP/1.1, HTTP/2, or WebSocket, the server may receive an invalid large (greater than 17408) TLS frame that is incorrectly handled, causing CPU resources to eventually reach 100% usage.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;The problem can be worked around by compiling the following class:
```java
package org.eclipse.jetty.server.ssl.fix6072;&lt;/p&gt;
&lt;p&gt;import java.nio.ByteBuffer;
import javax.net.ssl.SSLEngine;
import javax.net.ssl.SSLEngineResult;
import javax.net.ssl.SSLException;
import javax.net.ssl.SSLHandshakeException;&lt;/p&gt;
&lt;p&gt;import org.eclipse.jetty.io.EndPoint;
import org.eclipse.jetty.io.ssl.SslConnection;
import org.eclipse.jetty.server.Connector;
import org.eclipse.jetty.server.SslConnectionFactory;
import org.eclipse.jetty.util.BufferUtil;
import org.eclipse.jetty.util.annotation.Name;
import org.eclipse.jetty.util.ssl.SslContextFactory;&lt;/p&gt;
&lt;p&gt;public class SpaceCheckingSslConnectionFactory extends SslConnectionFactory
{
    public SpaceCheckingSslConnectionFactory(@Name(&amp;#34;sslContextFactory&amp;#34;) SslContextFactory factory, @Name(&amp;#34;next&amp;#34;) String nextProtocol)
    {
        super(factory, nextProtocol);
    }&lt;/p&gt;
&lt;p&gt;@Override
    protected SslConnection newSslConnection(Connector connector, EndPoint endPoint, SSLEngine engine)
    {
        return new SslConnection(connector.getByteBufferPool(), connector.getExecutor(), endPoint, engine, isDirectBuffersForEncryption(), isDirectBuffersForDecryption())
        {
            @Override
            protected SSLEn…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-26vr-8j45-3r4w</guid>
    </item>
    <item>
      <title>gsd-2021-28165</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28165</link>
      <description>gsd-2021-28165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28165</guid>
    </item>
    <item>
      <title>ICSMA-24-200-01 — Philips Vue PACS (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-24-200-01</link>
      <description>&lt;p&gt;Attackers can exploit this vulnerability by making numerous requests or sending large amounts of data to the application, leading to resource exhaustion (e.g., memory, CPU), which can cause the application to crash or become unresponsive. This vulnerability does not expose patient data or allow for its modification. It allows an attacker, with access to the hospital&amp;#39;s private network, which is protected by security controls (e.g., firewalls, VPNs), to send messages to the server, leading to potential CPU overload and a denial-of-service (DoS) condition. No response is sent back to the attacker, and patient information remains secure. The product does not require unique and complex passwords to be created during installation. Using Philips&amp;#39;s default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Attackers can exploit this vulnerability by making numerous requests or sending large amounts of data to the application, leading to resource exhaustion (e.g., memory, CPU), which can cause the application to crash or become unresponsive. This vulnerability does not expose patient data or allow for its modification. It allows an attacker, with access to the hospital&amp;#39;s private network, which is protected by security controls (e.g., firewalls, VPNs), to send messages to the server, leading to potential CPU overload and a denial-of-service (DoS) condition. No response is sent back to the attacker, and patient information remains secure. The product does not require unique and complex passwords to be created during installation. Using Philips&amp;#39;s default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-24-200-01</guid>
    </item>
    <item>
      <title>OESA-2021-1166 — jetty security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jetty&lt;/p&gt;
&lt;p&gt;%global desc \ Jetty is a 100% Java HTTP Server and Servlet Container. This means that you\ do not need to configure and run a separate web server (like Apache) in order\ to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully\ featured web server for static and dynamic content. Unlike separate\ server/container solutions, this means that your web server and web\ application run in the same process, without interconnection overheads\ and complications. Furthermore, as a pure java component, Jetty can be simply\ included in your application for demonstration, distribution or deployment.\ Jetty is available on all Java supported platforms. %{desc} %global extdesc %{desc}\ \ This package contains&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.(CVE-2020-27223)&#13;
&#13;
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.(CVE-2021-28165)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jetty&lt;/p&gt;
&lt;p&gt;%global desc \ Jetty is a 100% Java HTTP Server and Servlet Container. This means that you\ do not need to configure and run a separate web server (like Apache) in order\ to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully\ featured web server for static and dynamic content. Unlike separate\ server/container solutions, this means that your web server and web\ application run in the same process, without interconnection overheads\ and complications. Furthermore, as a pure java component, Jetty can be simply\ included in your application for demonstration, distribution or deployment.\ Jetty is available on all Java supported platforms. %{desc} %global extdesc %{desc}\ \ This package contains&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.(CVE-2020-27223)&#13;
&#13;
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.(CVE-2021-28165)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1166</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</link>
      <description>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1509 — Red Hat Security Advisory: rh-eclipse-jetty security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1509</link>
      <description>&lt;p&gt;jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1509</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</link>
      <description>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-28165</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28165</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1365 — Eclipse Jetty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</guid>
    </item>
  </channel>
</rss>
