{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/jetty-10/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-7708"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Jetty 10","Jetty 11"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","webserver","memory-leak"],"_cs_type":"advisory","_cs_vendors":["Eclipse"],"content_html":"\u003cp\u003eA high-severity memory leak vulnerability (CVE-2024-7708) has been identified in Eclipse Jetty, affecting versions 10.0.0 through 10.0.22 and 11.0.0 through 11.0.22. The flaw arises from the server's handling of HTTP \u003ccode\u003e100-Continue\u003c/code\u003e requests, specifically when the server attempts to read a request body but ends up reading zero bytes. This condition, which can be triggered by slow network conditions or malicious client behavior, causes a buffer to leak memory. An unauthenticated attacker can exploit this by repeatedly sending specially crafted requests, leading to memory exhaustion and an eventual \u003ccode\u003eOutOfMemory\u003c/code\u003e error. This resource depletion can render the Jetty server unresponsive, resulting in a Denial of Service (DoS) for legitimate users. There are no known workarounds other than patching.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a public-facing server running a vulnerable version of Eclipse Jetty (e.g., Jetty 11.0.22).\u003c/li\u003e\n\u003cli\u003eThe attacker initiates an HTTP POST request to the vulnerable Jetty server, including the \u003ccode\u003eExpect: 100-Continue\u003c/code\u003e header.\u003c/li\u003e\n\u003cli\u003eThe attacker then manipulates network conditions or client behavior to ensure that the server, after sending a \u003ccode\u003e100 Continue\u003c/code\u003e response, attempts to read the request body but reads zero bytes.\u003c/li\u003e\n\u003cli\u003eThis specific condition triggers a memory leak within the Jetty server process, where an allocated buffer is not properly released.\u003c/li\u003e\n\u003cli\u003eThe attacker continuously sends a high volume of these specially crafted HTTP requests to the vulnerable server.\u003c/li\u003e\n\u003cli\u003eRepeated exploitation of the memory leak causes a cumulative depletion of the server's available memory resources.\u003c/li\u003e\n\u003cli\u003eEventually, the Jetty server experiences an \u003ccode\u003eOutOfMemory\u003c/code\u003e error, leading to its crash or an unresponsive state.\u003c/li\u003e\n\u003cli\u003eThe Jetty server becomes unavailable to legitimate users, resulting in a Denial of Service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-7708 results in a Denial of Service (DoS) condition on the vulnerable Eclipse Jetty server. This can lead to the server process crashing or becoming entirely unresponsive, preventing legitimate users from accessing services or applications hosted on it. The impact includes service unavailability, potential data loss (if not properly handled during the crash), and reputational damage for affected organizations. All applications and services relying on vulnerable Jetty instances are at risk. There is no information available regarding the number of victims or specific sectors targeted, but any organization using unpatched Jetty 10 or 11 versions is susceptible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2024-7708 immediately by upgrading all affected Jetty servers to version 11.0.23 or 10.0.23.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e logs for unusual patterns or high volumes of HTTP requests containing the \u003ccode\u003eExpect: 100-Continue\u003c/code\u003e header originating from single or suspicious IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T23:00:19Z","date_published":"2026-07-22T23:00:19Z","id":"https://feed.craftedsignal.io/briefs/2026-07-eclipse-jetty-dos/","summary":"A memory leak vulnerability, CVE-2024-7708, in Eclipse Jetty's server handling of HTTP 100-Continue requests can be exploited by an attacker to trigger an OutOfMemory error, leading to a Denial of Service state for affected servers.","title":"Eclipse Jetty Denial of Service Vulnerability via 100-Continue Requests (CVE-2024-7708)","url":"https://feed.craftedsignal.io/briefs/2026-07-eclipse-jetty-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Jetty 10","version":"https://jsonfeed.org/version/1.1"}