DEBIAN-CVE-2026-1605

Source
https://security-tracker.debian.org/tracker/CVE-2026-1605
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1605.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-1605
Upstream
Published
2026-03-05T10:15:56.890Z
Modified
2026-03-11T07:39:12.806362Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.

References

Affected packages

Debian:13 / jetty12

Package

Name
jetty12
Purl
pkg:deb/debian/jetty12?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.17-3
12.0.17-3.1~deb13u1
12.0.17-3.1
12.0.32-1
12.0.32-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1605.json"

Debian:14 / jetty12

Package

Name
jetty12
Purl
pkg:deb/debian/jetty12?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.0.32-1

Affected versions

12.*
12.0.17-3
12.0.17-3.1~deb13u1
12.0.17-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1605.json"