Junglewise Threat Intelligence

CVE-2026-12611: Eclipse Jetty HTTP/2 thread exhaustion via race condition in frame handling

CVE-2026-12611 · Severity: info · CVSS 8.7 · Published 2026-09-08

Vendors: Eclipse.

Executive brief

Eclipse Jetty is a widely-used Java web server that handles HTTP/2 connections. A race condition in how it processes HTTP/2 control frames (RST_STREAM and GOAWAY) can cause write operations to become permanently blocked, eventually exhausting all server threads and rendering the entire server unresponsive. An attacker on the network can trigger this by sending specially crafted HTTP/2 requests followed by stream reset and connection close frames.

Technical details

The vulnerability is a race condition in HTTP2Flusher state management when processing RST_STREAM and GOAWAY frames concurrently. When a client sends a RST_STREAM followed by GOAWAY, the two frames may be processed by different threads. If GOAWAY is processed first, it closes the endpoint and causes the RST_STREAM write to fail, setting HTTP2Flusher.terminated to a non-null value. However, the concurrent processing can later reset terminated back to null, allowing new flush entries to be enqueued. Since the flusher's iteration loop has already stopped after the initial failure, these enqueued flush entries are never processed, leaving write-blocked threads permanently stuck. The attack requires network access to send malicious HTTP/2 frames; no authentication or user interaction is needed. This causes denial of service through thread exhaustion and server unresponsiveness.

Affected products

  • Eclipse Jetty 9.4.36 to 9.4.63, 10.0.0 to 10.0.31, 11.0.0 to 11.0.31, 12.0.0 to 12.0.37, 12.1.0 to 12.1.10

Timeline

  • 2026-09-16: disclosed: GitHub advisory GHSA-gpg9-4257-cfm3 published
  • 2026-09: patched: Patches released: 9.4.64, 10.0.32, 11.0.32, 12.0.38, 12.1.11

References