VYPR
High severity7.5NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026

CVE-2022-2048

CVE-2022-2048

Description

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.eclipse.jetty.http2:http2-serverMaven
< 9.4.479.4.47
org.eclipse.jetty.http2:http2-serverMaven
>= 10.0.0, < 10.0.1010.0.10
org.eclipse.jetty.http2:http2-serverMaven
>= 11.0.0, < 11.0.1011.0.10

Affected products

13

Patches

Vulnerability mechanics

References

8

News mentions

1