{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-1605",
        "tracking": {
            "current_release_date": "2026-03-27T07:27:19.011210Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-1605",
            "initial_release_date": "2026-03-05T10:25:01.235958Z",
            "revision_history": [
                {
                    "date": "2026-03-05T10:25:01.235958Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T10:25:03.581961Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-05T10:38:46.810905Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T10:38:55.118066Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T12:19:00.621729Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Products created (2).| References created (4)."
                },
                {
                    "date": "2026-03-05T12:19:02.519367Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T14:29:14.455202Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-05T14:29:20.273159Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T15:35:25.197587Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T15:38:41.627394Z",
                    "number": "10",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-05T21:40:04.229490Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T21:40:07.622761Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T00:15:46.601094Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (31).| Product Identifiers created (38).| Products connected (9).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-06T00:15:50.534546Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T00:27:40.455209Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (35).| Product Identifiers created (24).| Products created (17).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-06T00:27:45.876181Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T12:43:02.487826Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source."
                },
                {
                    "date": "2026-03-06T20:26:53.654607Z",
                    "number": "18",
                    "summary": "Products created (2).| Product Identifiers created (2)."
                },
                {
                    "date": "2026-03-06T20:26:57.909159Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T23:39:40.443574Z",
                    "number": "20",
                    "summary": "CWES updated (1)."
                },
                {
                    "date": "2026-03-07T00:15:44.051767Z",
                    "number": "21",
                    "summary": "CWES updated (1)."
                },
                {
                    "date": "2026-03-20T10:10:36.979616Z",
                    "number": "22",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-26T09:11:37.827833Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-03-26T09:11:43.247505Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "24"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/12.0.0|<=12.0.31",
                                "product": {
                                    "name": "vers:semver/12.0.0|<=12.0.31",
                                    "product_id": "CSAFPID-5761761"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/12.1.0|<=12.1.5",
                                "product": {
                                    "name": "vers:semver/12.1.0|<=12.1.5",
                                    "product_id": "CSAFPID-5761762"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Eclipse Jetty"
                    }
                ],
                "category": "vendor",
                "name": "Eclipse Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<12.0.32",
                                "product": {
                                    "name": "vers:unknown/<12.0.32",
                                    "product_id": "CSAFPID-5761976"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<12.1.6",
                                "product": {
                                    "name": "vers:unknown/<12.1.6",
                                    "product_id": "CSAFPID-5761975"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jetty"
                    }
                ],
                "category": "vendor",
                "name": "Eclipse"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=12.0.0|<12.0.32",
                                "product": {
                                    "name": "vers:unknown/>=12.0.0|<12.0.32",
                                    "product_id": "CSAFPID-5767376",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=12.1.0|<12.1.6",
                                "product": {
                                    "name": "vers:unknown/>=12.1.0|<12.1.6",
                                    "product_id": "CSAFPID-5767377",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jetty"
                    }
                ],
                "category": "vendor",
                "name": "Elipse"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1441072",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ocp_tools"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Developer Tools and Services"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439334",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_broker:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat AMQ Broker 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439292",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Data Grid 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439294",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_fuse:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Fuse 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439300",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439302",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439304",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jbosseapxp"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439390",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Web Server 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-2855757",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:offline_knowledge_portal:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Offline Knowledge Portal"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1441150",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Dev Spaces"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439306",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Process Automation 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439313",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:satellite:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439308",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Single Sign-On 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-2467441",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:rhboac_hawtio:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apache Camel - HawtIO 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439286",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:camel_spring_boot:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apache Camel for Spring Boot 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2467443",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_registry:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apicurio Registry 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-2656600",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:apicurio_registry:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apicurio Registry 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2783932",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:debezium:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Debezium 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-2783934",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:debezium:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Debezium 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2425594"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jenkins"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441074"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jenkins-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-4684006"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jenkins-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Developer Tools and Services"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764393"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat AMQ Broker 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764400"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Data Grid 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764401"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Fuse 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764402"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764403"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764404"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764405"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Web Server 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764406"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Process Automation 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764407"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Single Sign-On 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764395"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apache Camel - HawtIO 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764394"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apache Camel for Spring Boot 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764396"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apicurio Registry 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764397"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apicurio Registry 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764398"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Debezium 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764399"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Debezium 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764408"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "streams for Apache Kafka 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5764409"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetty-server"
                            }
                        ],
                        "category": "product_family",
                        "name": "streams for Apache Kafka 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2876356"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jmc"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2895521"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "resteasy"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2972742"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "maven-wagon"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-4534155"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "openvsx-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2577689"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pluginregistry-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Dev Spaces"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2821660"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "puppetserver"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2895520"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "resteasy"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2855758"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhokp-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Offline Knowledge Portal"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2467457",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_streams:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "streams for Apache Kafka 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-3026117",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_streams:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "streams for Apache Kafka 3"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<12.5",
                                "product": {
                                    "name": "vers:unknown/<12.5",
                                    "product_id": "CSAFPID-5915936"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PDFreactor"
                    }
                ],
                "category": "vendor",
                "name": "RealObjects"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.0",
                                "product": {
                                    "name": "vers:unknown/12.0.0",
                                    "product_id": "CSAFPID-5536511",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.1",
                                "product": {
                                    "name": "vers:unknown/12.0.1",
                                    "product_id": "CSAFPID-5536512",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.10",
                                "product": {
                                    "name": "vers:unknown/12.0.10",
                                    "product_id": "CSAFPID-5764031",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.11",
                                "product": {
                                    "name": "vers:unknown/12.0.11",
                                    "product_id": "CSAFPID-5764032",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.12",
                                "product": {
                                    "name": "vers:unknown/12.0.12",
                                    "product_id": "CSAFPID-5764033",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.13",
                                "product": {
                                    "name": "vers:unknown/12.0.13",
                                    "product_id": "CSAFPID-5764034",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.14",
                                "product": {
                                    "name": "vers:unknown/12.0.14",
                                    "product_id": "CSAFPID-5764035",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.15",
                                "product": {
                                    "name": "vers:unknown/12.0.15",
                                    "product_id": "CSAFPID-5764036",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.16",
                                "product": {
                                    "name": "vers:unknown/12.0.16",
                                    "product_id": "CSAFPID-5764037",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.17",
                                "product": {
                                    "name": "vers:unknown/12.0.17",
                                    "product_id": "CSAFPID-5764038",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.18",
                                "product": {
                                    "name": "vers:unknown/12.0.18",
                                    "product_id": "CSAFPID-5764039",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.19",
                                "product": {
                                    "name": "vers:unknown/12.0.19",
                                    "product_id": "CSAFPID-5764040",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.2",
                                "product": {
                                    "name": "vers:unknown/12.0.2",
                                    "product_id": "CSAFPID-5536513",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.20",
                                "product": {
                                    "name": "vers:unknown/12.0.20",
                                    "product_id": "CSAFPID-5764041",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.20"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.21",
                                "product": {
                                    "name": "vers:unknown/12.0.21",
                                    "product_id": "CSAFPID-5764042",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.21"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.22",
                                "product": {
                                    "name": "vers:unknown/12.0.22",
                                    "product_id": "CSAFPID-5764043",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.22"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.23",
                                "product": {
                                    "name": "vers:unknown/12.0.23",
                                    "product_id": "CSAFPID-5764044",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.23"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.24",
                                "product": {
                                    "name": "vers:unknown/12.0.24",
                                    "product_id": "CSAFPID-5764045",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.25",
                                "product": {
                                    "name": "vers:unknown/12.0.25",
                                    "product_id": "CSAFPID-5764046",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.25"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.26",
                                "product": {
                                    "name": "vers:unknown/12.0.26",
                                    "product_id": "CSAFPID-5764047",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.26"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.27",
                                "product": {
                                    "name": "vers:unknown/12.0.27",
                                    "product_id": "CSAFPID-5764048",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.27"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.28",
                                "product": {
                                    "name": "vers:unknown/12.0.28",
                                    "product_id": "CSAFPID-5764049",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.28"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.29",
                                "product": {
                                    "name": "vers:unknown/12.0.29",
                                    "product_id": "CSAFPID-5764050",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.29"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.3",
                                "product": {
                                    "name": "vers:unknown/12.0.3",
                                    "product_id": "CSAFPID-5536514",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.30",
                                "product": {
                                    "name": "vers:unknown/12.0.30",
                                    "product_id": "CSAFPID-5764051",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.30"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.31",
                                "product": {
                                    "name": "vers:unknown/12.0.31",
                                    "product_id": "CSAFPID-5764052",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.31"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.4",
                                "product": {
                                    "name": "vers:unknown/12.0.4",
                                    "product_id": "CSAFPID-5536515",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.5",
                                "product": {
                                    "name": "vers:unknown/12.0.5",
                                    "product_id": "CSAFPID-5536516",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.6",
                                "product": {
                                    "name": "vers:unknown/12.0.6",
                                    "product_id": "CSAFPID-5536517",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.7",
                                "product": {
                                    "name": "vers:unknown/12.0.7",
                                    "product_id": "CSAFPID-5536518",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.8",
                                "product": {
                                    "name": "vers:unknown/12.0.8",
                                    "product_id": "CSAFPID-5536519",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0.9",
                                "product": {
                                    "name": "vers:unknown/12.0.9",
                                    "product_id": "CSAFPID-5764053",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.0",
                                "product": {
                                    "name": "vers:unknown/12.1.0",
                                    "product_id": "CSAFPID-5764024",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.1",
                                "product": {
                                    "name": "vers:unknown/12.1.1",
                                    "product_id": "CSAFPID-5764025",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.2",
                                "product": {
                                    "name": "vers:unknown/12.1.2",
                                    "product_id": "CSAFPID-5764026",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.3",
                                "product": {
                                    "name": "vers:unknown/12.1.3",
                                    "product_id": "CSAFPID-5764027",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.4",
                                "product": {
                                    "name": "vers:unknown/12.1.4",
                                    "product_id": "CSAFPID-5764028",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.1.5",
                                "product": {
                                    "name": "vers:unknown/12.1.5",
                                    "product_id": "CSAFPID-5764029",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.eclipse.jetty/jetty-server@12.1.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=12.0.0|<12.0.32",
                                "product": {
                                    "name": "vers:unknown/>=12.0.0|<12.0.32",
                                    "product_id": "CSAFPID-5764054"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=12.1.0|<12.1.6",
                                "product": {
                                    "name": "vers:unknown/>=12.1.0|<12.1.6",
                                    "product_id": "CSAFPID-5764030"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "jetty-server"
                    }
                ],
                "category": "vendor",
                "name": "jetty"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-1605",
            "cwe": {
                "id": "CWE-401",
                "name": "Missing Release of Memory after Effective Lifetime"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.\n\n\nThis happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.\nIn this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-1605"
                },
                {
                    "category": "description",
                    "text": "In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.\n\n\nThis happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.\nIn this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-1605"
                },
                {
                    "category": "description",
                    "text": "### Description (as reported)\n\nThere is a memory leak when using `GzipHandler` in jetty-12.0.30 that can cause off-heap OOMs. This can be used for DoS attacks so I'm reporting this as a vulnerability.\n\nThe leak is created by requests where the request is inflated (`Content-Encoding: gzip`) and the response is not deflated (no `Accept-Encoding: gzip`). In these conditions, a new inflator will be created by `GzipRequest` and never released back into `GzipRequest.__inflaterPool` because `gzipRequest.destory()` is not called.\n\nIn heap dumps one can see thousands of `java.util.zip.Inflator` objects, which use both Java heaps and native memory. Leaking native memory causes of off-heap OOMs.\n\nCode path in `GzipHandler.handle()`:\n1. Line 601: `GzipRequest` is created when request inflation is needed.\n2. Lines 611-616: The callback is only wrapped in `GzipResponseAndCallback` when both inflation and deflation are needed.\n3. Lines 619-625: If the handler accepts the request (returns true), `gzipRequest.destroy()` is only called in the \"request not accepted\" path (returns false)\n\nWhen deflation is needed, `GzipResponseAndCallback` (lines 102 and 116) properly calls `gzipRequest.destroy()` in its `succeeded()` and `failed()` methods. But this wrapper is only created when deflation is needed.\n\nPossible fix:\nThe callback should be wrapped whenever a `GzipRequest` is created, not just when deflation is needed. This ensures `gzipRequest.destroy()` is always called when the request completes.\n\n\n### Impact\nThe leak causes the JVM to crash with OOME.\n\n### Patches\nNo patches yet.\n\n### Workarounds\nDisable `GzipHandler`.\n\n### References\nhttps://github.com/jetty/jetty.project/issues/14260\n\nhttps://gitlab.eclipse.org/security/cve-assignment/-/issues/79",
                    "title": "github - https://github.com/advisories/GHSA-xxh7-fcf3-rj7f"
                },
                {
                    "category": "description",
                    "text": "### Description (as reported)\n\nThere is a memory leak when using `GzipHandler` in jetty-12.0.30 that can cause off-heap OOMs. This can be used for DoS attacks so I'm reporting this as a vulnerability.\n\nThe leak is created by requests where the request is inflated (`Content-Encoding: gzip`) and the response is not deflated (no `Accept-Encoding: gzip`). In these conditions, a new inflator will be created by `GzipRequest` and never released back into `GzipRequest.__inflaterPool` because `gzipRequest.destory()` is not called.\n\nIn heap dumps one can see thousands of `java.util.zip.Inflator` objects, which use both Java heaps and native memory. Leaking native memory causes of off-heap OOMs.\n\nCode path in `GzipHandler.handle()`:\n1. Line 601: `GzipRequest` is created when request inflation is needed.\n2. Lines 611-616: The callback is only wrapped in `GzipResponseAndCallback` when both inflation and deflation are needed.\n3. Lines 619-625: If the handler accepts the request (returns true), `gzipRequest.destroy()` is only called in the \"request not accepted\" path (returns false)\n\nWhen deflation is needed, `GzipResponseAndCallback` (lines 102 and 116) properly calls `gzipRequest.destroy()` in its `succeeded()` and `failed()` methods. But this wrapper is only created when deflation is needed.\n\nPossible fix:\nThe callback should be wrapped whenever a `GzipRequest` is created, not just when deflation is needed. This ensures `gzipRequest.destroy()` is always called when the request completes.\n\n\n### Impact\nThe leak causes the JVM to crash with OOME.\n\n### Patches\nNo patches yet.\n\n### Workarounds\nDisable `GzipHandler`.\n\n### References\nhttps://github.com/jetty/jetty.project/issues/14260\n\nhttps://gitlab.eclipse.org/security/cve-assignment/-/issues/79",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-xxh7-fcf3-rj7f.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in org.eclipse.jetty. A remote attacker can exploit this vulnerability by sending a compressed HTTP request with Content-Encoding: gzip when the server's response is not compressed. This prevents the release of the JDK Inflater, leading to a resource leak. This resource exhaustion can result in a Denial of Service (DoS), making the server unavailable to legitimate users.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-1605"
                },
                {
                    "category": "description",
                    "text": "In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.   This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-1605"
                },
                {
                    "category": "other",
                    "text": "0.00055",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "5.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5761761",
                    "CSAFPID-5761762",
                    "CSAFPID-5761975",
                    "CSAFPID-5761976",
                    "CSAFPID-5536511",
                    "CSAFPID-5536512",
                    "CSAFPID-5536513",
                    "CSAFPID-5536514",
                    "CSAFPID-5536515",
                    "CSAFPID-5536516",
                    "CSAFPID-5536517",
                    "CSAFPID-5536518",
                    "CSAFPID-5536519",
                    "CSAFPID-5764024",
                    "CSAFPID-5764025",
                    "CSAFPID-5764026",
                    "CSAFPID-5764027",
                    "CSAFPID-5764028",
                    "CSAFPID-5764029",
                    "CSAFPID-5764030",
                    "CSAFPID-5764031",
                    "CSAFPID-5764032",
                    "CSAFPID-5764033",
                    "CSAFPID-5764034",
                    "CSAFPID-5764035",
                    "CSAFPID-5764036",
                    "CSAFPID-5764037",
                    "CSAFPID-5764038",
                    "CSAFPID-5764039",
                    "CSAFPID-5764040",
                    "CSAFPID-5764041",
                    "CSAFPID-5764042",
                    "CSAFPID-5764043",
                    "CSAFPID-5764044",
                    "CSAFPID-5764045",
                    "CSAFPID-5764046",
                    "CSAFPID-5764047",
                    "CSAFPID-5764048",
                    "CSAFPID-5764049",
                    "CSAFPID-5764050",
                    "CSAFPID-5764051",
                    "CSAFPID-5764052",
                    "CSAFPID-5764053",
                    "CSAFPID-5764054",
                    "CSAFPID-1439302",
                    "CSAFPID-1439304",
                    "CSAFPID-1439334",
                    "CSAFPID-1441072",
                    "CSAFPID-1441074",
                    "CSAFPID-1441150",
                    "CSAFPID-2425594",
                    "CSAFPID-2467441",
                    "CSAFPID-2577689",
                    "CSAFPID-3026117",
                    "CSAFPID-4534155",
                    "CSAFPID-4684006",
                    "CSAFPID-5764393",
                    "CSAFPID-5764395",
                    "CSAFPID-5764403",
                    "CSAFPID-5764404",
                    "CSAFPID-5764409",
                    "CSAFPID-5767376",
                    "CSAFPID-5767377",
                    "CSAFPID-5915936"
                ],
                "known_not_affected": [
                    "CSAFPID-1439286",
                    "CSAFPID-1439292",
                    "CSAFPID-1439294",
                    "CSAFPID-1439300",
                    "CSAFPID-1439306",
                    "CSAFPID-1439308",
                    "CSAFPID-1439313",
                    "CSAFPID-1439315",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1439390",
                    "CSAFPID-2467443",
                    "CSAFPID-2467457",
                    "CSAFPID-2656600",
                    "CSAFPID-2783932",
                    "CSAFPID-2783934",
                    "CSAFPID-2821660",
                    "CSAFPID-2855757",
                    "CSAFPID-2855758",
                    "CSAFPID-2876356",
                    "CSAFPID-2895520",
                    "CSAFPID-2895521",
                    "CSAFPID-2972742",
                    "CSAFPID-5764394",
                    "CSAFPID-5764396",
                    "CSAFPID-5764397",
                    "CSAFPID-5764398",
                    "CSAFPID-5764399",
                    "CSAFPID-5764400",
                    "CSAFPID-5764401",
                    "CSAFPID-5764402",
                    "CSAFPID-5764405",
                    "CSAFPID-5764406",
                    "CSAFPID-5764407",
                    "CSAFPID-5764408"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/1xxx/CVE-2026-1605.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0604.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-xxh7-fcf3-rj7f"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-xxh7-fcf3-rj7f"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-xxh7-fcf3-rj7f.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-1605.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0862.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0604.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0604"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; github; osv",
                    "url": "https://gitlab.eclipse.org/security/cve-assignment/-/issues/79"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/jetty/jetty.project/issues/14260"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-xxh7-fcf3-rj7f"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-1605"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0862.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0862"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.pdfreactor.com/pdfreactor-12-5/"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1439302",
                        "CSAFPID-1439304",
                        "CSAFPID-1439334",
                        "CSAFPID-1441072",
                        "CSAFPID-1441074",
                        "CSAFPID-1441150",
                        "CSAFPID-2425594",
                        "CSAFPID-2467441",
                        "CSAFPID-2577689",
                        "CSAFPID-3026117",
                        "CSAFPID-4534155",
                        "CSAFPID-4684006",
                        "CSAFPID-5536511",
                        "CSAFPID-5536512",
                        "CSAFPID-5536513",
                        "CSAFPID-5536514",
                        "CSAFPID-5536515",
                        "CSAFPID-5536516",
                        "CSAFPID-5536517",
                        "CSAFPID-5536518",
                        "CSAFPID-5536519",
                        "CSAFPID-5761761",
                        "CSAFPID-5761762",
                        "CSAFPID-5761975",
                        "CSAFPID-5761976",
                        "CSAFPID-5764024",
                        "CSAFPID-5764025",
                        "CSAFPID-5764026",
                        "CSAFPID-5764027",
                        "CSAFPID-5764028",
                        "CSAFPID-5764029",
                        "CSAFPID-5764030",
                        "CSAFPID-5764031",
                        "CSAFPID-5764032",
                        "CSAFPID-5764033",
                        "CSAFPID-5764034",
                        "CSAFPID-5764035",
                        "CSAFPID-5764036",
                        "CSAFPID-5764037",
                        "CSAFPID-5764038",
                        "CSAFPID-5764039",
                        "CSAFPID-5764040",
                        "CSAFPID-5764041",
                        "CSAFPID-5764042",
                        "CSAFPID-5764043",
                        "CSAFPID-5764044",
                        "CSAFPID-5764045",
                        "CSAFPID-5764046",
                        "CSAFPID-5764047",
                        "CSAFPID-5764048",
                        "CSAFPID-5764049",
                        "CSAFPID-5764050",
                        "CSAFPID-5764051",
                        "CSAFPID-5764052",
                        "CSAFPID-5764053",
                        "CSAFPID-5764054",
                        "CSAFPID-5764393",
                        "CSAFPID-5764395",
                        "CSAFPID-5764403",
                        "CSAFPID-5764404",
                        "CSAFPID-5764409",
                        "CSAFPID-5767376",
                        "CSAFPID-5767377",
                        "CSAFPID-5915936"
                    ]
                }
            ],
            "title": "CVE-2026-1605"
        }
    ]
}