客户端可能发送带有未知操作码(opcode)和极大声明负载长度的 WebSocket 帧,导致 Jetty 尝试进行大内存分配,从而可能耗尽 JVM 堆内存。 该问题在启用自动分片(auto-fragmentation)时发生,因为未知操作码会绕过常规的最大帧大小处理逻辑,且负载分配发生在操作码校验之前。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Jetty | 12.1.0 ~ 12.1.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84173 | 8.3 HIGH | CVE-2026-84173 |
| CVE-2026-85201 | 6.8 MEDIUM | Eclipse Ankaios 0.1.0-1.0.1 内存分配越界漏洞 |
No comments yet