The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
History

Fri, 06 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
Title org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
Weaknesses CWE-444
References
Metrics threat_severity

None

threat_severity

Low


Thu, 05 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2026-03-05T09:26:59.830Z

Updated: 2026-03-05T14:48:41.622Z

Reserved: 2025-09-29T05:08:52.530Z

Link: CVE-2025-11143

cve-icon Vulnrichment

Updated: 2026-03-05T14:48:32.138Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-05T10:15:54.680

Modified: 2026-03-05T19:38:33.877

Link: CVE-2025-11143

cve-icon Redhat

Severity : Low

Publid Date: 2026-03-05T09:26:59Z

Links: CVE-2025-11143 - Bugzilla