Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-6763

20
FAUCET Score

CVE-2024-6763 is a medium-severity vulnerability affecting Eclipse Jetty's HttpURI utility class, which insufficiently validates the authority segment of URIs. This flaw can lead to discrepancies between how Jetty and common browsers interpret invalid URIs, potentially enabling open redirect or Server-Side Request Forgery (SSRF) attacks if the URI is used after validation. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and a potential impact on integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0.0, < 9.4.57CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 7.0.0, <= 12.0.11CPE match
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.97%
Probability of exploitation in next 30 days
EPSS Percentile
58.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0097 is in the 36th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-httpFixed in: 12.0.12
nodejspatch availablevia llm_extracted
Fixed in: 5.4.3
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 3.0.0
View patch
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 2.9.1
View patch
redhatvendor investigatingvia redhat_api
Product: A-MQ Clients 2Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel 4 for Quarkus 3Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 3Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 4Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel - HawtIO 4Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Debezium 2Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Build of KeycloakFixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: org.eclipse.jetty/jetty-http-spi
redhatvendor investigatingvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: org.eclipse.jetty/jetty-http-spi
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.eclipse.jetty/jetty-http-spi
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.eclipse.jetty/jetty-http-spi
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Web Server 6Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Process Automation 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: streams for Apache KafkaFixed in: org.eclipse.jetty/jetty-http
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: org.eclipse.jetty/jetty-http

Vendor Advisories (3)

nodejsllm-nodejs-91bc25f14cc604adCRITICAL

Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025

Jul 30, 2025
mavenGHSA-qh8g-58pp-2wxhmedium

Eclipse Jetty URI parsing of invalid authority

Oct 14, 2024
redhatCVE-2024-6763Low

org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority

Oct 14, 2024

References

security.netapp.com / advisory/ntap-20250306-0005
Third Party Advisory
github.com / jetty/jetty.project/pull/12012
PatchThird Party Advisory
github.com / jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh
ExploitMitigationVendor Advisory
gitlab.eclipse.org / security/cve-assignement/-/issues/25
Vendor Advisory