{"id":"GHSA-xxh7-fcf3-rj7f","summary":"The Eclipse Jetty Server Artifact has a Gzip request memory leak ","details":"### Description (as reported)\n\nThere is a memory leak when using `GzipHandler` in jetty-12.0.30 that can cause off-heap OOMs. This can be used for DoS attacks so I'm reporting this as a vulnerability.\n\nThe leak is created by requests where the request is inflated (`Content-Encoding: gzip`) and the response is not deflated (no `Accept-Encoding: gzip`). In these conditions, a new inflator will be created by `GzipRequest` and never released back into `GzipRequest.__inflaterPool` because `gzipRequest.destory()` is not called.\n\nIn heap dumps one can see thousands of `java.util.zip.Inflator` objects, which use both Java heaps and native memory. Leaking native memory causes of off-heap OOMs.\n\nCode path in `GzipHandler.handle()`:\n1. Line 601: `GzipRequest` is created when request inflation is needed.\n2. Lines 611-616: The callback is only wrapped in `GzipResponseAndCallback` when both inflation and deflation are needed.\n3. Lines 619-625: If the handler accepts the request (returns true), `gzipRequest.destroy()` is only called in the \"request not accepted\" path (returns false)\n\nWhen deflation is needed, `GzipResponseAndCallback` (lines 102 and 116) properly calls `gzipRequest.destroy()` in its `succeeded()` and `failed()` methods. But this wrapper is only created when deflation is needed.\n\nPossible fix:\nThe callback should be wrapped whenever a `GzipRequest` is created, not just when deflation is needed. This ensures `gzipRequest.destroy()` is always called when the request completes.\n\n\n### Impact\nThe leak causes the JVM to crash with OOME.\n\n### Patches\nNo patches yet.\n\n### Workarounds\nDisable `GzipHandler`.\n\n### References\nhttps://github.com/jetty/jetty.project/issues/14260\n\nhttps://gitlab.eclipse.org/security/cve-assignment/-/issues/79","aliases":["CVE-2026-1605"],"modified":"2026-07-17T21:14:24.945673512Z","published":"2026-03-05T21:27:59Z","database_specific":{"cwe_ids":["CWE-400","CWE-401"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-05T21:27:59Z","nvd_published_at":"2026-03-05T10:15:56Z"},"references":[{"type":"WEB","url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1605"},{"type":"WEB","url":"https://github.com/jetty/jetty.project/issues/14260"},{"type":"PACKAGE","url":"https://github.com/jetty/jetty.project"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/79"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.1.0"},{"fixed":"12.1.6"}]}],"versions":["12.1.0","12.1.1","12.1.2","12.1.3","12.1.4","12.1.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.1.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xxh7-fcf3-rj7f/GHSA-xxh7-fcf3-rj7f.json"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.0.32"}]}],"versions":["12.0.0","12.0.1","12.0.10","12.0.11","12.0.12","12.0.13","12.0.14","12.0.15","12.0.16","12.0.17","12.0.18","12.0.19","12.0.2","12.0.20","12.0.21","12.0.22","12.0.23","12.0.24","12.0.25","12.0.26","12.0.27","12.0.28","12.0.29","12.0.3","12.0.30","12.0.31","12.0.4","12.0.5","12.0.6","12.0.7","12.0.8","12.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 12.0.31","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xxh7-fcf3-rj7f/GHSA-xxh7-fcf3-rj7f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}