Vulnerability record · CVE-2020-27223 · published 26 February 2021
CVE-2020-27223: Eclipse Jetty Accept header q-parameter parsing causes CPU exhaustion DoS
Eclipse · Jetty
Jetty versions 9.4.6.v20170531 through 9.4.36.v20210114, plus 10.0.0 and 11.0.0, mishandle requests with multiple Accept headers containing many quality (q) parameters. Processing those values consumes minutes of CPU time, driving the server into a denial-of-service state. The flaw is remotely reachable and requires no authentication.
Description
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score, though CVSS rates it medium and it is not in KEV.
What it is
Jetty versions 9.4.6.v20170531 through 9.4.36.v20210114, plus 10.0.0 and 11.0.0, mishandle requests with multiple Accept headers containing many quality (q) parameters. Processing those values consumes minutes of CPU time, driving the server into a denial-of-service state. The flaw is remotely reachable and requires no authentication.
Impact
An unauthenticated attacker can exhaust server CPU and make the Jetty service unresponsive for extended periods. The CVSS vector shows availability impact only, with no confidentiality or integrity loss.
Attack surface
Reached over the network via HTTP by sending crafted Accept headers with a large number of q parameters; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.7795 (99.5th percentile), indicating elevated predicted exploitation activity. References are vendor advisories and commit/issue links, with no public exploit tag supplied.
What to do
- Upgrade Jetty to a version after 9.4.36.v20210114, or to a fixed 10.x/11.x release, per the vendor advisory and commit.
- Patch or update downstream products that bundle Jetty, including Apache NiFi, Spark, Solr, and NetApp/Oracle components listed in the record.
- Where immediate patching is not possible, front the service with a reverse proxy or WAF rule that limits Accept header count and q-parameter length.
- Monitor and rate-limit inbound requests with unusually large or numerous Accept headers.
Detection
- Alert on HTTP requests containing multiple Accept headers or an abnormal number of q parameters.
- Monitor Jetty process CPU for sustained spikes correlated with request volume from a single source.
- Baseline normal Accept header sizes and flag outliers in web server or proxy logs.
- Watch for repeated requests from one client that drive CPU saturation without corresponding application activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-27223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.