In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.10.3 for Spring Boot Via RHSA-2025:7696 https://access.redhat.com/errata/RHSA-2025:7696
This issue has been addressed in the following products: OCP-Tools-4.18-RHEL-9 Via RHSA-2025:10092 https://access.redhat.com/errata/RHSA-2025:10092
This issue has been addressed in the following products: OCP-Tools-4.17-RHEL-9 Via RHSA-2025:10097 https://access.redhat.com/errata/RHSA-2025:10097
This issue has been addressed in the following products: OCP-Tools-4.16-RHEL-9 Via RHSA-2025:10098 https://access.redhat.com/errata/RHSA-2025:10098
This issue has been addressed in the following products: OCP-Tools-4.15-RHEL-8 Via RHSA-2025:10104 https://access.redhat.com/errata/RHSA-2025:10104
This issue has been addressed in the following products: OCP-Tools-4.13-RHEL-8 Via RHSA-2025:10119 https://access.redhat.com/errata/RHSA-2025:10119
This issue has been addressed in the following products: OCP-Tools-4.12-RHEL-8 Via RHSA-2025:10118 https://access.redhat.com/errata/RHSA-2025:10118
This issue has been addressed in the following products: OCP-Tools-4.14-RHEL-8 Via RHSA-2025:10120 https://access.redhat.com/errata/RHSA-2025:10120
This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.1 Via RHSA-2025:13274 https://access.redhat.com/errata/RHSA-2025:13274