Org.eclipse.jetty.http2:http2-server
This hub aggregates every CVE we track for Org.eclipse.jetty.http2:http2-server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
2
CVEs tracked
0
Critical
2
High
1
In CISA KEV
Severity distribution
HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 2 most recently published vulnerabilities affecting Org.eclipse.jetty.http2:http2-server.
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2022-2048In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associa...7.5
Product normalization is registry-driven with AI assist and human review. How it works