CVE-2025-12383 - CVE House
Back to Database
Status published Critical CVE-2025-12383

Race Condition allows Bypass of Trust Restrictions

Vulnerability Description

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12383

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Dimitri Tenenbaum

Affected Vendor

Eclipse Foundation

View all reports →

Affected Software

Jersey
Vulnerable Versions:
2.45, 3.0.16, 3.1.9

Timeline

Official Publish: November 18th, 2025
Last Modified: November 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)