CVE-2024-7708: High severity requests vulnerability

Published Jul 14, 2026
·
Updated

Impact The original report:

> Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.

After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

Affected Versions

Jetty 11.0.0-11.0.22 (EOL) Jetty 10.0.0-10.0.22 (EOL)

Patched Versions

Jetty 11.0.23 Jetty 10.0.23

Patches

https://github.com/jetty/jetty.project/pull/12156

Workarounds

No workarounds.

Other sources

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

NVD

Affected Software

5 affected componentsFixes available
requests
Eclipse Jetty>=10.0.7<10.0.23
Eclipse Jetty>=11.0.7<11.0.23
maven/org.eclipse.jetty:jetty-server>=11.0.7<11.0.23
11.0.23
maven/org.eclipse.jetty:jetty-server>=10.0.7<10.0.23
10.0.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.eclipse.jetty:jetty-server to a version that resolves this vulnerability.

    Fixed in 11.0.23
  2. Upgrade

    Upgrade maven/org.eclipse.jetty:jetty-server to a version that resolves this vulnerability.

    Fixed in 10.0.23
  3. Upgrade

    Upgrade Jetty to a version that resolves this vulnerability.

    Fixed in 10.0.23
  4. Upgrade

    Upgrade Jetty to a version that resolves this vulnerability.

    Fixed in 11.0.23

Event History

Jul 14, 2026
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Advisory Published
via GitHub·10:58 PM
Data Sourced
via GitHub·10:58 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-7708?

The severity of CVE-2024-7708 is high with a score of 7.5.

2

What are the main risks associated with CVE-2024-7708?

CVE-2024-7708 poses a risk of sensitive data exposure due to a buffer leak that can occur with slow network requests.

3

How do I fix CVE-2024-7708?

To fix CVE-2024-7708, ensure that body reading and buffer handling mechanisms are properly implemented to prevent leaks.

4

What types of requests are affected by CVE-2024-7708?

CVE-2024-7708 affects requests that contain a body, particularly in situations involving a slow network or 100-Continue responses.

5

Is there a workaround for CVE-2024-7708 until a patch is available?

A possible workaround for CVE-2024-7708 is to restrict the usage of body data in requests where performance concerns exist.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203