Jetty
Vendor:
First CVE: Oct 7, 2016 · Active for 9 years
51
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jetty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2016
9 years ago
Most Recent CVE
Jul 14, 2026
9 days ago
CVE Severity & Scoring
Jetty51 CVEs
41%
41%
10%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.0%)
Network49 (96.1%)
Unknown0 (0.0%)
Physical1 (2.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (92.2%)
High4 (7.8%)
Unknown0 (0.0%)
User Interaction
None48 (94.1%)
Unknown0 (0.0%)
Required3 (5.9%)
Privileges Required
Low6 (11.8%)
High2 (3.9%)
None43 (84.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2015-2080HIGH The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP he | Oct 7, 2016 | 7.5 | 78 | NO | YES |
CVE-2021-28169MEDIUM For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB | Jun 9, 2021 | 5.3 | 74 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
CVE-2017-7658CRITICAL In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers | Jun 26, 2018 | 9.8 | 41 | NO | NO |
CVE-2017-7657CRITICAL In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled | Jun 26, 2018 | 9.8 | 39 | NO | NO |
CVE-2026-2332CRITICAL In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.i | Apr 14, 2026 | 9.1 | 37 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (51 CVEs).
CISA KEV
1 CVE
2.0% of CVEs· 96th percentile
Metasploit
2 CVEs
3.9% of CVEs· 96th percentile
Nuclei
4 CVEs
7.8% of CVEs· 97th percentile
ExploitDB
4 CVEs
7.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (51 CVEs).
Media Mentions
Signals from CVEs in this product scope (51 CVEs).
Top CNAs Publishing CVEs For Jetty
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.9 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.8 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.7 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.6 | 4 | 6.0 | 24.6% | 0 | 0 |
| 9.4.5 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.4 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.38 | 1 | 5.3 | 82.4% | 0 | 1 |
| 9.4.37 | 1 | 5.3 | 82.4% | 0 | 1 |
| 9.4.36 | 1 | 5.3 | 78.0% | 0 | 0 |
| 9.4.3 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.29 | 1 | 9.4 | 11.1% | 0 | 0 |
| 9.4.28 | 1 | 9.4 | 11.1% | 0 | 0 |
| 9.4.27 | 1 | 9.4 | 11.1% | 0 | 0 |
| 9.4.23 | 1 | 6.1 | 1.9% | 0 | 0 |
| 9.4.22 | 1 | 6.1 | 1.9% | 0 | 0 |
| 9.4.21 | 1 | 6.1 | 1.9% | 0 | 0 |
| 9.4.2 | 3 | 6.3 | 6.8% | 0 | 0 |
| 9.4.16 | 1 | 5.3 | 4.0% | 0 | 0 |
| 9.4.15 | 2 | 5.7 | 7.7% | 0 | 0 |
| 9.4.14 | 2 | 5.7 | 7.7% | 0 | 0 |