ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-27223

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
An official patch is available. Apply the patch as soon as possible.
5.2
CVSS
1.5
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorAdjacent
ComplexityLow
RequirementsPresent
PrivilegesLow
User InteractionActive
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusOfficial Patch

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P0.6 → 1.5
2026-07-21cve.orginitial, patch: Official Patch0.6

Affected Software
VendorProductVersion
apachenifi1.13.0
apachesolr8.8.1
apachespark3.1.1
debiandebian_linux10.0
eclipsejetty≥ 9.4.7, < 9.4.36
eclipsejetty10.0.0
eclipsejetty11.0.0
eclipsejetty9.4.36
eclipsejetty9.4.6
netappe-series_santricity_os_controller≥ 11.0.0, ≤ 11.70.1
netappe-series_santricity_web_servicesAll versions
netappelement_plug-in_for_vcenter_serverAll versions
netapphciAll versions
netapphci_management_nodeAll versions
netappmanagement_services_for_element_softwareAll versions
netappsnap_creator_frameworkAll versions
netappsnapcenterAll versions
netappsnapmanagerAll versions
netappsolidfireAll versions
oraclerest_data_services< 20.4.3.050.1904
The Eclipse FoundationEclipse Jetty≤ 9.4.36.v20210114
The Eclipse FoundationEclipse Jetty10.0.0
The Eclipse FoundationEclipse Jetty11.0.0
The Eclipse FoundationEclipse Jetty9.4.6.v20170531
Published: 2021-02-26