Executive brief
Eclipse Jetty, a widely used web server and servlet container, contains a memory leak vulnerability in its GzipHandler component. When the server processes a compressed request but sends back an uncompressed response, it fails to release internal memory resources. An attacker can exploit this by sending many such requests, eventually causing the server to run out of memory and crash, leading to a denial of service.
Technical details
A memory leak exists in the Eclipse Jetty GzipHandler due to improper resource management of the JDK Inflater. When a request is received with 'Content-Encoding: gzip', a GzipRequest object is created and an Inflater is allocated from the pool. However, the release mechanism (gzipRequest.destroy()) is tied to the GzipResponseAndCallback wrapper, which is only instantiated if the response is also compressed. If the response is not compressed (e.g., missing 'Accept-Encoding: gzip'), the Inflater is never returned to the pool. Remote, unauthenticated attackers can exploit this by sending repeated compressed requests to trigger an OutOfMemoryError (OOME) and crash the JVM. The issue is patched in versions 12.0.32 and 12.1.6.
Affected products
- Eclipse Foundation Jetty 12.0.0-12.0.31, 12.1.0-12.1.5
Timeline
- 2026-03-05: advisory: Initial disclosure by Eclipse Foundation
- 2026-03-05: disclosed
- 2026-05-28: patched: Red Hat released updates for OpenShift Dev Spaces
References
- https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/errata/RHSA-2026:25089
- https://access.redhat.com/errata/RHSA-2026:25125
- https://access.redhat.com/errata/RHSA-2026:25126
- https://access.redhat.com/errata/RHSA-2026:8509
- https://access.redhat.com/security/cve/CVE-2026-1605