← Back

CVE-2025-11143

nvd nist
Published: Mar 5, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.

Affected (5)

Products: Eclipse: Jetty
1 product
Jetty
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 10.0.0 to 10.0.26
From 11.0.0 to 11.0.26
From 12.0.0 to 12.0.31
From 12.1.0 to 12.1.5
From 9.4.0 to 9.4.58

References (1)

Timeline

No history available yet.