The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
History

Fri, 06 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse jetty
Vendors & Products Eclipse
Eclipse jetty

Fri, 06 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
Title org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
Weaknesses CWE-444
References
Metrics threat_severity

None

threat_severity

Low


Thu, 05 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-03-05T14:48:41.622Z

Reserved: 2025-09-29T05:08:52.530Z

Link: CVE-2025-11143

cve-icon Vulnrichment

Updated: 2026-03-05T14:48:32.138Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-05T10:15:54.680

Modified: 2026-03-06T20:30:58.117

Link: CVE-2025-11143

cve-icon Redhat

Severity : Low

Publid Date: 2026-03-05T09:26:59Z

Links: CVE-2025-11143 - Bugzilla