{"id":"CVE-2024-13009","aliases":["GHSA-q4rv-gq96-w7c5"],"url":"https://o3.security/vulnerability/CVE-2024-13009","summary":"Eclipse Jetty GZIP buffer release","details":"In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request\nbody. This can result in corrupted and/or inadvertent sharing of data between requests.","published":"2025-05-08T17:29:31.380Z","modified":"2026-09-06T03:45:44.811626890Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":{"score":0.00525,"percentile":0.43059,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.eclipse.jetty:jetty-server","fixedVersion":"9.4.57.v20241219"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/13xxx/CVE-2024-13009.json"},{"type":"ADVISORY","url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-q4rv-gq96-w7c5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-13009"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/cve-assignement/-/issues/48"},{"type":"PACKAGE","url":"https://github.com/jetty/jetty.project"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T03:45:44.811626890Z"}}