CVE-2025-11143

Published: Mar 05, 2026 Last Modified: Mar 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 3,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0006
Percentile
0,2th
Updated

EPSS Score Trend (Last 11 Days)

20

Improper Input Validation

Stable
Common Consequences
Security Scopes Affected:
Availability Confidentiality Integrity
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Read Memory Read Files Or Directories Modify Memory Execute Unauthorized Code Or Commands
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Jetty by Eclipse

Version Range Affected
From 12.1.0 (inclusive)
To 12.1.5 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 11.0.0 (inclusive)
To 11.0.26 (inclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 10.0.0 (inclusive)
To 10.0.26 (inclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 9.4.0 (inclusive)
To 9.4.58 (inclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jetty by Eclipse

Version Range Affected
From 12.0.0 (inclusive)
To 12.0.31 (exclusive)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh