Memory leak in Jetty - CVE-2026-1605

 

Memory leak in Jetty - CVE-2026-1605

Published: March 5, 2026


Vulnerability identifier: #VU123577
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1605
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within the GzipHandler component when parsing HTTP requests. A remote attacker can send specially crafted HTTP requests to the application, force it to leak memory and perform denial of service attack.


Affected software

Jetty
IBM Sterling B2B Integrator
IBM Sterling Control Center
IBM Sterling File Gateway
IBM Engineering Systems Design Rhapsody
MongoDB Enterprise Advanced with IBM

How to mitigate CVE-2026-1605

Install updates from vendor's website.

Jetty - addressed in versions 12.0.32, 12.1.6
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling Control Center - addressed in versions 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3
IBM Engineering Systems Design Rhapsody - addressed in versions 10.0.0.5, 10.0.1.0.5, 10.0.2.0.4
MongoDB Enterprise Advanced with IBM - update to 1.16.0

External References

Related Security Bulletins