CVE-2024-8184: Eclipse Jetty

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.

Affected products

  • Eclipse Jetty: from 9.3.12, before 9.4.56 (fixed in 9.4.56); from 10.0.0, before 10.0.24 (fixed in 10.0.24); from 11.0.0, before 11.0.24 (fixed in 11.0.24); from 12.0.0, before 12.0.9 (fixed in 12.0.9)

Published 2024-10-14. Last modified 2026-06-17.