CVE-2026-19204

Summary

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.

This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationEclipse Jetty12.1.0 <= 12.1.11affected
Eclipse FoundationEclipse Jetty12.0.0 <= 12.0.37affected
Eclipse FoundationEclipse Jetty11.0.0 <= 11.0.31affected
Eclipse FoundationEclipse Jetty10.0.0 <= 10.0.31affected

Weaknesses

  • CWE-770: CWE-770 Allocation of resources without limits or throttling
  • CWE-789: CWE-789 Memory allocation with excessive size value

References