Description
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4949-1 | jetty9 security update |
Github GHSA |
GHSA-m394-8rww-3jr7 | DOS vulnerability for Quoted Quality CSV headers |
References
History
Wed, 20 Aug 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Subscriptions
Apache
Subscribe
Nifi
Subscribe
Solr
Subscribe
Spark
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Eclipse
Subscribe
Jetty
Subscribe
Netapp
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Web Services
Subscribe
Element Plug-in For Vcenter Server
Subscribe
Hci
Subscribe
Hci Management Node
Subscribe
Management Services For Element Software
Subscribe
Snap Creator Framework
Subscribe
Snapcenter
Subscribe
Snapmanager
Subscribe
Solidfire
Subscribe
Oracle
Subscribe
Rest Data Services
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Fuse
Subscribe
Openshift
Subscribe
Rhmt
Subscribe
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-08-20T10:03:37.386Z
Reserved: 2020-10-19T00:00:00.000Z
Link: CVE-2020-27223
No data.
Status : Modified
Published: 2021-02-26T22:15:19.317
Modified: 2025-08-20T10:15:27.843
Link: CVE-2020-27223
OpenCVE Enrichment
No data.
Debian DSA
Github GHSA