Answer in brief
CVE-2025-11143 records a Low severity (CVSS 3.7) vulnerability in org.eclipse.jetty:jetty-http has different parsing of invalid URIs. The current sources do not mark it as known exploited. The current feed maps org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven), org.eclipse.jetty:jetty-http (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| org.eclipse.jetty:jetty-httpmaven | >=9.4.0 | Not reported |
| org.eclipse.jetty:jetty-httpmaven | >=10.0.0 | Not reported |
| org.eclipse.jetty:jetty-httpmaven | >=11.0.0 | Not reported |
| org.eclipse.jetty:jetty-httpmaven | >=12.0.0 <12.0.31 | 12.0.31 |
| org.eclipse.jetty:jetty-httpmaven | >=12.1.0 <12.1.5 | 12.1.5 |
Published upstream
Mar 5, 2026
Evidence: source:osv:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:osv:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
The Jetty URI parser has some key differences compared to other common parsers when evaluating invalid or unusual URIs. Specifically: #### Invalid Scheme | URI | Jetty | uri-js (nodejs) | node-url(nodejs) | |---|---|---| --- | | `https>://vulndetector.com/path` | scheme=`http>`| scheme=`https` | invalid URI | #### Improper IPv4 mapped IPv6 | URI | Jetty | System.Uri(CSharp) | curl(C) | |---|---|---| --- | | `http://[0:0:0:0:0:ffff:127.0.0.1]` | invalid | host=`[::ffff:127.0.0.1]` | host=`[::ffff:127.0.0.1]` | | `http://[::ffff:255.255.0.0]` | invalid | host=`[::ffff:255.255.0.0]` | host=`[::ffff:255.255.0.0]` | #### Incorrect IPv6 delimeter priority | URI | Jetty | urllib3(python) | furl(python) | Spring | chromium | |---|---|---| --- |---|---| | `http://[normal.com@]vulndetector.com/` | host=`[normal.com@]` | invalid | invalid | | | | `http://normal.com[user@vulndetector].com/` | host=`[noirmal.com@vulndetector | | | host=`normal.com` | invalid | | `http://normal.com[@]vulndetector.com/` | host=`normal.com[@] | | | host=`normal.com` | invalid | #### Incorrect delimeter priority | URI | Jetty | urllib3(python) | jersey | |---|---|---| --- | | `http://normal.com/#@vulndetector.com` | host=`vulndetector.com` | host=`normal.com` | host=`normal.com` | | `http://normal.com/[email protected]` | host=`vulndetector.com` | host=`normal.com` | host=`normal.com` | ### Impact Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details. ### Patches Patched in Supported Open Source versions. * 12.1.5 - Supported and available on Maven Central * 12.0.31 - Supported and available on Maven Central * 11.0.x - EOL Release, patches available on [tuxcare](https://tuxcare.com/) and [herodevs](https://www.herodevs.com/) * 10.0.x - EOL Release, patches available on [tuxcare](https://tuxcare.com/) and [herodevs](https://www.herodevs.com/) * 9.4.x - EOL Release, patches available on [tuxcare](https://tuxcare.com/) and [herodevs](https://www.herodevs.com/) ### Workarounds None ### Resources + [Java Eclipse Jetty Report_ Incorrect Parsing Priority of the IPv6 Hostname Delimeter.pdf](https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf) + [Java Eclipse Jetty Report_ The Parsing Priority of the Delimiter.pdf](https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf) + [Java Eclipse Jetty Report_ Parsing Difference Due to Deformed Scheme.pdf](https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf) + [Java Eclipse Jetty Report_ Improper IPv4-mapped IPv6 Parsing.pdf](https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf)
Quoted source text, attributed separately from HOL analysis.