{"id":"CVE-2025-12383","aliases":["GHSA-7p63-w6x9-6gr7"],"url":"https://o3.security/vulnerability/CVE-2025-12383","summary":"Race Condition allows Bypass of Trust Restrictions","details":"In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)","published":"2025-11-18T15:14:37.765Z","modified":"2026-08-12T03:51:28.215752467Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.glassfish.jersey.core:jersey-client","fixedVersion":"2.46"},{"ecosystem":"Maven","name":"org.glassfish.jersey.core:jersey-client","fixedVersion":"3.0.17"},{"ecosystem":"Maven","name":"org.glassfish.jersey.core:jersey-client","fixedVersion":"3.1.10"}],"fix":{"url":"https://github.com/eclipse-ee4j/jersey/pull/5749","label":"eclipse-ee4j/jersey#5749"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12383.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12383"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/74"},{"type":"PACKAGE","url":"https://github.com/eclipse-ee4j/jersey"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/pull/5749"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/pull/5794"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/commit/425bc883d8d623ef8d3c448fafd36729f7741bcb"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/commit/b2c7ba6d388cb9722f39073d7e82aa818fec49d5"},{"type":"WEB","url":"https://github.com/dtbaum/jerseyCveCandidate"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/2.46"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/3.0.17"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/3.1.10"},{"type":"WEB","url":"https://github.com/eclipse-ee4j/jersey/releases/tag/4.0.0-M2"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/253"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.215752467Z"}}