Junglewise Threat Intelligence

CVE-2026-19204: Eclipse Jetty WebSocket denial of service via reserved opcode

CVE-2026-19204 · Severity: info · CVSS 7.5 · Published 2026-09-07

Vendors: Eclipse.

Executive brief

Jetty is an open-source web server and servlet container widely used to handle HTTP and WebSocket connections. An attacker can send a specially crafted WebSocket frame with a reserved opcode and an extremely large declared payload size, causing the server to attempt a multi-gigabyte memory allocation and crash with an out-of-memory error, resulting in service unavailability.

Technical details

The vulnerability exists in Jetty's WebSocket frame parser (Parser.java). When auto-fragmentation is enabled (the default), the parser calls checkFrameSize() to validate frame size, but this method skips the maxFrameSize check for non-control frames when auto-fragmentation is on. Reserved opcodes (e.g., 0x03) are neither control nor data frames, so they bypass both size guards. The parser then calls parsePayload(), which attempts to allocate bufferPool.acquire(payloadLength, false) with the full attacker-declared payload length (up to Integer.MAX_VALUE ≈ 2 GiB) before validating the opcode. The opcode validation via OpCode.isKnown() occurs only after allocation, making it too late. A 15-byte WebSocket frame header can trigger a ~2 GiB heap allocation and cause OutOfMemoryError. Patches are available in versions 10.0.32, 11.0.32, 12.0.38, and 12.1.12.

Affected products

  • Eclipse Jetty 10.0.0 through 10.0.31, 11.0.0 through 11.0.31, 12.0.0 through 12.0.37, 12.1.0 through 12.1.11

Timeline

  • 2026-09-16: disclosed
  • 2026-09-07: advisory
  • 2026-09-16: patched: Patches released: 10.0.32, 11.0.32, 12.0.38, 12.1.12

References