CVE-2025-1948
HighAdvisory
Published 8 May 2025In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3
- of 17,781 indexed, latest versions
- Container images
- 3
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 3 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-http2-commonmaven | 12.0.9, 12.0.16 | 12.0.17 | 3 |
- OSV records
- GHSA-889j-63jv-qhr8
Charts affected
3 by stars
Container images carrying it
3 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| resurfaceio/ | d5cda2f64109 | jetty-http2-common | 12.0.17 | 1 |
| trinodb/ | 38c6f24ab1a4 | jetty-http2-common | 12.0.17 | 1 |
| public.ecr.aws/ | c265156b00d1 | jetty-http2-common | 12.0.17 | 1 |