{"id":"GHSA-7p63-w6x9-6gr7","summary":"Eclipse Jersey has a Race Condition","details":"In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)","aliases":["CVE-2025-12383"],"modified":"2026-07-17T21:14:05.631358768Z","published":"2025-11-18T18:32:51Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-11-18T20:38:31Z","nvd_published_at":"2025-11-18T16:15:42Z","cwe_ids":["CWE-296","CWE-362"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12383"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/pull/5749"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/pull/5794"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/commit/425bc883d8d623ef8d3c448fafd36729f7741bcb"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/commit/b2c7ba6d388cb9722f39073d7e82aa818fec49d5"},{"type":"WEB","url":"https://github.com/dtbaum/jerseyCveCandidate"},{"type":"PACKAGE","url":"https://github.com/eclipse-ee4j/jersey"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/2.46"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/3.0.17"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/3.1.10"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/4.0.0-M2"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/74"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/253"}],"affected":[{"package":{"name":"org.glassfish.jersey.core:jersey-client","ecosystem":"Maven","purl":"pkg:maven/org.glassfish.jersey.core/jersey-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.45"},{"fixed":"2.46"}]}],"versions":["2.45"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7p63-w6x9-6gr7/GHSA-7p63-w6x9-6gr7.json"}},{"package":{"name":"org.glassfish.jersey.core:jersey-client","ecosystem":"Maven","purl":"pkg:maven/org.glassfish.jersey.core/jersey-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.16"},{"fixed":"3.0.17"}]}],"versions":["3.0.16"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7p63-w6x9-6gr7/GHSA-7p63-w6x9-6gr7.json"}},{"package":{"name":"org.glassfish.jersey.core:jersey-client","ecosystem":"Maven","purl":"pkg:maven/org.glassfish.jersey.core/jersey-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.9"},{"fixed":"3.1.10"}]}],"versions":["3.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7p63-w6x9-6gr7/GHSA-7p63-w6x9-6gr7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}]}