CVE-2026-1605
Summary
| CVE | CVE-2026-1605 |
|---|---|
| State | PUBLISHED |
| Assigner | eclipse |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-05 10:15:56 UTC |
| Updated | 2026-08-27 13:16:57 UTC |
| Description | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-400 | CWE-401 | CWE-772 | CWE-400 CWE-400 Uncontrolled Resource Consumption | CWE-401 CWE-401 Missing Release of Memory after Effective Lifetime | CWE-772 Missing Release of Resource after Effective Lifetime
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Eclipse Foundation | Eclipse Jetty | affected 12.0.0 12.0.31 semver | Not specified |
| CNA | Eclipse Foundation | Eclipse Jetty | affected 12.1.0. 12.1.5 semver | Not specified |
| ADP | Red Hat | HawtIO HawtIO 4.4.0 | Not specified | Not specified |
| ADP | Red Hat | Red Hat AMQ Broker 7.14.0 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 8 | unaffected 0:2.40.0-7.redhat_00015.1.el8eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 8 | unaffected 0:801.6.1-1.GA_redhat_00001.1.el8eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 8 | unaffected 0:2.3.24-3.SP2_redhat_00001.1.el8eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 8 | unaffected 0:8.1.6-7.GA_redhat_00010.1.el8eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 9 | unaffected 0:2.40.0-7.redhat_00015.1.el9eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 9 | unaffected 0:801.6.1-1.GA_redhat_00001.1.el9eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 9 | unaffected 0:2.3.24-3.SP2_redhat_00001.1.el9eap * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 For RHEL 9 | unaffected 0:8.1.6-7.GA_redhat_00010.1.el9eap * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.12 | unaffected 1786628667 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.13 | unaffected 1786628681 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.14 | unaffected 1786533561 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.15 | unaffected 1786533565 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.16 | unaffected 1787125166 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.17 | unaffected 1787124635 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.18 | unaffected 1787125069 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.19 | unaffected 1787124632 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.20 | unaffected 1787124925 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.21 | unaffected 1787125311 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services 4.22 | unaffected 1787124779 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Dev Spaces 3.28 | unaffected 1779528224 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift Dev Spaces 3.28 | unaffected 1779359423 * rpm | Not specified |
| ADP | Red Hat | OpenShift Developer Tools And Services | Not specified | Not specified |
| ADP | Red Hat | Red Hat Build Of Apache Camel For Spring Boot 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Build Of Apicurio Registry 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Build Of Apicurio Registry 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Build Of Debezium 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Build Of Debezium 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Data Grid 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Fuse 7 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform 7 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Offline Knowledge Portal | Not specified | Not specified |
| ADP | Red Hat | Red Hat Process Automation 7 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Single Sign-On 7 | Not specified | Not specified |
| ADP | Red Hat | Streams For Apache Kafka 2 | Not specified | Not specified |
| ADP | Red Hat | Streams For Apache Kafka 3 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:60250 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-1605 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f | [email protected] | github.com | Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:60248 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60247 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:25125 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:8509 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60252 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:25089 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1605.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:25126 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60259 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60256 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60239 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:21772 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60254 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60251 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60246 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60249 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Gleb Sizov (@glebashnik) (en)
CNA: Bjørn Christian Seime (@bjorncs) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-03-05T11:00:57.250Z | Reported to Red Hat. |
| ADP | 2026-03-05T09:39:01.315Z | Made public. |
Solutions
ADP: RHSA-2026:25125: Red Hat JBoss EAP 8.1 for RHEL 8, Red Hat JBoss EAP 8.1 for RHEL 9
ADP: RHSA-2026:25089: HawtIO HawtIO 4.4.0
ADP: RHSA-2026:60247: OpenShift Developer Tools and Services 4.12
ADP: RHSA-2026:60249: OpenShift Developer Tools and Services 4.13
ADP: RHSA-2026:60248: OpenShift Developer Tools and Services 4.14
ADP: RHSA-2026:60239: OpenShift Developer Tools and Services 4.15
ADP: RHSA-2026:60251: OpenShift Developer Tools and Services 4.16
ADP: RHSA-2026:60246: OpenShift Developer Tools and Services 4.17
ADP: RHSA-2026:60250: OpenShift Developer Tools and Services 4.18
ADP: RHSA-2026:60252: OpenShift Developer Tools and Services 4.19
ADP: RHSA-2026:60259: OpenShift Developer Tools and Services 4.20
ADP: RHSA-2026:60254: OpenShift Developer Tools and Services 4.21
ADP: RHSA-2026:60256: OpenShift Developer Tools and Services 4.22
ADP: RHSA-2026:8509: Red Hat AMQ Broker 7.14.0
ADP: RHSA-2026:25126: Red Hat JBoss Enterprise Application Platform 8.1
ADP: RHSA-2026:21772: Red Hat OpenShift Dev Spaces 3.28
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.