Bug 2529344 (CVE-2026-19204) - CVE-2026-19204 org.eclipse.jetty.websocket/websocket-core-common: Jetty: Denial of Service via crafted WebSocket frame with unknown opcode
Summary: CVE-2026-19204 org.eclipse.jetty.websocket/websocket-core-common: Jetty: Deni...
Keywords:
Status: NEW
Alias: CVE-2026-19204
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-07 10:41 UTC by OSIDB Bzimport
Modified: 2026-09-21 18:42 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-07 10:41:37 UTC
A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap.




This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.


Note You need to log in before you can comment on or make changes to this bug.