Home

Description

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.

PUBLISHED Reserved 2025-09-29 | Published 2026-03-05 | Updated 2026-03-05 | Assigner eclipse




LOW: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

9.4.0 (semver)
affected

10.0.0 (semver)
affected

11.0.0 (semver)
affected

12.0.0 (semver)
affected

12.1.0 (semver)
affected

Credits

zer0yu finder

References

github.com/...roject/security/advisories/GHSA-wjpw-4j6x-6rwh

cve.org (CVE-2025-11143)

nvd.nist.gov (CVE-2025-11143)

Download JSON