An open index of dependabot pull requests across open source projects.

org.eclipse.jetty:jetty-server

Ecosystem:
maven
Package URL:
pkg:maven/org.eclipse.jetty:jetty-server
Total PRs:
500 Dependabot PRs
Latest PR:
2 months ago
Unique Repositories:
232 repositories
Unique Repos (30 days):
3 repositories
Security Advisories
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
GHSA-9299-c6m4-mjhc CVE-2024-7708 HIGH published 7 days ago • updated 1 day ago
### Impact The original report: > Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service...
Jetty Uses Predictable Session Identifiers
GHSA-jg2x-r643-w2ch CVE-2006-6969 MODERATE published about 4 years ago • updated about 13 hours ago
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random...
The Eclipse Jetty Server Artifact has a Gzip request memory leak
GHSA-xxh7-fcf3-rj7f CVE-2026-1605 HIGH published 5 months ago • updated 1 day ago
### Description (as reported) There is a memory leak when using `GzipHandler` in jetty-12.0.30 that can cause off-heap OOMs. This can be used for ...
Eclipse Jetty Server generates error message containing sensitive information
GHSA-9rgv-h7x4-qw8g CVE-2018-12536 MODERATE published almost 8 years ago • updated about 1 month ago
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't m...
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
GHSA-g8m5-722r-8whq CVE-2024-8184 MODERATE published almost 2 years ago • updated 8 days ago
### Impact Remote DOS attack can cause out of memory ### Description There exists a security vulnerability in Jetty's `ThreadLimitHandler.getRemo...
Recent PRs
Bump the maven group across 9 directories with 21 updates

yathin51/tutorials #18

9.4.19.v20190610 → 9.4.56.v20240826 Patch PR
Closed 5 months ago 1 comment
yathin51
Bump the maven group across 4 directories with 1 update

Cynive/NetworkDataAPI #4

9.4.48.v20220622 → 9.4.56.v20240826 Patch PR
Closed 9 months ago 2 comments
Cynive
Package Details
Name: org.eclipse.jetty:jetty-server
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/org.eclipse.jetty:jetty-server
JSON API: View JSON
Security Advisories

29

Active advisories
CRITICAL 4
HIGH 10
MODERATE 13
LOW 2
View All maven Advisories
Package Information
Description:

The legacy jetty server artifact.

Repository: https://github.com/jetty/jetty.project
Homepage: https://jetty.org
Latest Release: 12.0.15
over 1 year ago
Dependent Repos: 34,580
Dependent Packages: 3,819
Ranking: Top 0.0272% by dependent repos Top 0.017% by dependent pkgs
PR Status
Open 196 (39.2%)
Merged 124 (24.8%)
Closed 130 (26.0%)
PR Types
Major 67 (13.4%)
Minor 54 (10.8%)
Patch 324 (64.8%)