CWE-400 Uncontrolled Resource Consumption in Eclipse Foundation Eclipse Jetty (CVE-2026-1605)
Red Hat AMQ Broker 7.14.0 includes multiple security fixes addressing vulnerabilities in components such as Eclipse Jetty, Netty HTTP/HTTP2 codecs, Apache ZooKeeper, and Apache Artemis. These issues range from denial of service, request smuggling, impersonation via DNS spoofing, information disclosure, to unauthorized address creation during JMS topic subscription. The update is rated as important by Red Hat Product Security and addresses six distinct CVEs. Users should apply the update to mitigate these vulnerabilities.
AI Analysis
Technical Summary
Eclipse Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 contain a vulnerability in the GzipHandler component. When a compressed HTTP request with Content-Encoding: gzip is processed but the response is not compressed, the JDK Inflater used for decompression is allocated but not released. The release mechanism is tied to the compressed response, so if the response is uncompressed, the Inflater resource leaks. This uncontrolled resource consumption can lead to denial of service conditions.
Potential Impact
The vulnerability can cause denial of service by leaking JDK Inflater resources when handling compressed HTTP requests without compressed responses. This resource leak can exhaust system resources, potentially degrading or interrupting service availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Red Hat has issued security updates addressing this vulnerability in Red Hat JBoss Enterprise Application Platform 8.1, which includes Eclipse Jetty fixes. Applying the official security update from Red Hat (RHSA-2026:25125) will remediate the issue. Users should ensure all relevant errata are applied and back up their systems before updating. Patch status is confirmed by the vendor advisory, and a fix is available.
CWE-400 Uncontrolled Resource Consumption in Eclipse Foundation Eclipse Jetty (CVE-2026-1605)
Description
Red Hat AMQ Broker 7.14.0 includes multiple security fixes addressing vulnerabilities in components such as Eclipse Jetty, Netty HTTP/HTTP2 codecs, Apache ZooKeeper, and Apache Artemis. These issues range from denial of service, request smuggling, impersonation via DNS spoofing, information disclosure, to unauthorized address creation during JMS topic subscription. The update is rated as important by Red Hat Product Security and addresses six distinct CVEs. Users should apply the update to mitigate these vulnerabilities.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Eclipse Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 contain a vulnerability in the GzipHandler component. When a compressed HTTP request with Content-Encoding: gzip is processed but the response is not compressed, the JDK Inflater used for decompression is allocated but not released. The release mechanism is tied to the compressed response, so if the response is uncompressed, the Inflater resource leaks. This uncontrolled resource consumption can lead to denial of service conditions.
Potential Impact
The vulnerability can cause denial of service by leaking JDK Inflater resources when handling compressed HTTP requests without compressed responses. This resource leak can exhaust system resources, potentially degrading or interrupting service availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Red Hat has issued security updates addressing this vulnerability in Red Hat JBoss Enterprise Application Platform 8.1, which includes Eclipse Jetty fixes. Applying the official security update from Red Hat (RHSA-2026:25125) will remediate the issue. Users should ensure all relevant errata are applied and back up their systems before updating. Patch status is confirmed by the vendor advisory, and a fix is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:8509
- Cve Count
- 6
- Additional Cves
- ["CVE-2026-24281","CVE-2026-24308","CVE-2026-32642","CVE-2026-33870","CVE-2026-33871"]
- Cvss Version
- null
Threat ID: 6a160984e29bf47b50650c34
Added to database: 05/26/2026, 20:58:44 UTC
Last enriched: 07/15/2026, 16:11:22 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 129
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.