Jetty is a lightweight, embedded HTTP server and servlet container widely deployed in Java applications and microservices, with its vulnerability footprint concentrated entirely in the core server product. The recurring exposure centers on path-traversal and directory-access weaknesses inherent to HTTP request handling, and public exploit code has frequently become available for disclosed flaws. Defenders should prioritize updates to this component, particularly in internet-facing deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jetty over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1178MEDIUM Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences i | Oct 11, 2002 | 5.0 | 26 | NO | YES |
CVE-2002-1533MEDIUM Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contai | Mar 31, 2003 | 5.8 | 24 | NO | YES |
CVE-2006-2758MEDIUM Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the | Jun 2, 2006 | 5.0 | 23 | NO | YES |
CVE-2004-2478HIGH Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11 | Dec 31, 2004 | 7.5 | 20 | NO | NO |
CVE-2006-6969MEDIUM Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remot | Feb 7, 2007 | 6.8 | 19 | NO | NO |
CVE-2006-2759MEDIUM jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations. | Jun 2, 2006 | 5.0 | 15 | NO | NO |
CVE-2004-2381MEDIUM HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-L | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jetty.
Media articles that mention a CVE ID that affects a product developed by Jetty — matched by CVE ID, not by vendor name.