The Jetty URI parser has some key differences to other...
Vulnerability Description
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11143
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- zer0yu
More from Eclipse Foundation
View All →Affected Vendor
Eclipse Foundation
View all reports →