CVE-2024-7708: Eclipse Jetty

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

Affected products

  • Eclipse Jetty: from 10.0.7, before 10.0.23 (fixed in 10.0.23); from 11.0.7, before 11.0.23 (fixed in 11.0.23)

Published 2026-07-14. Last modified 2026-10-02.