This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jetty WebSocket Frame Memory Exhaustion via Unknown Opcode and Large Payload | |
| First Time appeared |
Eclipse
Eclipse jetty |
|
| Vendors & Products |
Eclipse
Eclipse jetty |
Mon, 07 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload allocation occurs before the opcode is validated. | |
| Weaknesses | CWE-770 CWE-789 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-09-07T10:19:24.186Z
Reserved: 2026-08-07T07:33:05.744Z
Link: CVE-2026-19204
No data.
Status : Received
Published: 2026-09-07T11:17:20.600
Modified: 2026-09-07T11:17:20.600
Link: CVE-2026-19204
No data.
OpenCVE Enrichment
Updated: 2026-09-07T13:30:16Z