Vulnerability record · CVE-2021-28165 · published 1 April 2021
CVE-2021-28165: Eclipse Jetty TLS frame handling causes CPU exhaustion
Eclipse · Jetty
Eclipse Jetty versions 7.2.2 through 9.4.38, 10.0.0.alpha0 through 10.0.1, and 11.0.0.alpha0 through 11.0.1 can consume 100% CPU when a large invalid TLS frame is received. The flaw is uncontrolled resource consumption in TLS frame processing, allowing a remote unauthenticated attacker to degrade or deny service.
Description
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 and very high EPSS with public exploit material make this a serious availability risk for exposed Jetty TLS endpoints.
What it is
Eclipse Jetty versions 7.2.2 through 9.4.38, 10.0.0.alpha0 through 10.0.1, and 11.0.0.alpha0 through 11.0.1 can consume 100% CPU when a large invalid TLS frame is received. The flaw is uncontrolled resource consumption in TLS frame processing, allowing a remote unauthenticated attacker to degrade or deny service.
Impact
An attacker can drive the Jetty process to full CPU utilization, causing service slowdown or denial of service for legitimate users. No data confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network via the TLS listener; the CVSS vector shows no privileges required and no user interaction. Any exposed Jetty TLS endpoint is a candidate.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.53861 (99th percentile) and a GitHub advisory reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Eclipse Jetty to a fixed release outside the affected ranges (7.2.2-9.4.38, 10.0.0.alpha0-10.0.1, 11.0.0.alpha0-11.0.1).
- If immediate upgrade is not possible, restrict network access to Jetty TLS ports to trusted clients only.
- Apply vendor patches for downstream products that bundle Jetty (Oracle, Jenkins, NetApp).
- Monitor CPU usage on Jetty hosts and alert on sustained saturation.
- Consider rate limiting or connection limits at the TLS termination layer to reduce the impact of malformed frame floods.
Detection
- Monitor Jetty process CPU for sustained 100% utilization without corresponding legitimate traffic increases.
- Inspect TLS connection logs for repeated malformed or oversized TLS frames from single sources.
- Use network monitoring to detect anomalous TLS handshake or frame patterns targeting Jetty listeners.
- Correlate high CPU alerts with source IPs sending invalid TLS data.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-28165 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28165), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.