Skip to content

10.0.x HTTP2Session cleanups to address CVE-2025-5115#13462

Merged
joakime merged 2 commits into
jetty-10.0.xfrom
fix/jetty-10.0.x/h2session-cleanups
Aug 13, 2025
Merged

10.0.x HTTP2Session cleanups to address CVE-2025-5115#13462
joakime merged 2 commits into
jetty-10.0.xfrom
fix/jetty-10.0.x/h2session-cleanups

Conversation

@sbordet
Copy link
Copy Markdown
Contributor

@sbordet sbordet commented Aug 13, 2025

Various cleanups to address CVE-2025-5115
Updated mismatch in parameter configuration between code and XML files.

Various cleanups.
Updated mismatch in parameter configuration between code and XML files.

Signed-off-by: Simone Bordet <simone.bordet@gmail.com>
@sbordet sbordet requested review from joakime and lorban August 13, 2025 15:58
joakime
joakime previously approved these changes Aug 13, 2025
@joakime
Copy link
Copy Markdown
Contributor

joakime commented Aug 13, 2025

Test failures on SmallThreadPoolLoadTest.testConcurrentWithSmallServerThreadPool here.

Signed-off-by: Simone Bordet <simone.bordet@gmail.com>
@joakime joakime merged commit 0b1e539 into jetty-10.0.x Aug 13, 2025
11 checks passed
@joakime joakime deleted the fix/jetty-10.0.x/h2session-cleanups branch August 13, 2025 18:57
@joakime
Copy link
Copy Markdown
Contributor

joakime commented Aug 13, 2025

Merged to jetty-10.0.x and up to jetty-11.0.x

@joakime joakime changed the title 10.0.x HTTP2Session cleanups. 10.0.x HTTP2Session cleanups to address CVE-2025-5115 Aug 20, 2025
@joakime joakime added Unsupported Release For releases that are no longer supported Security labels Aug 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Security Unsupported Release For releases that are no longer supported

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants