Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7p63-w6x9-6gr7 | Eclipse Jersey has a Race Condition |
Fri, 16 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eclipse:jersey:2.45:*:*:*:*:*:*:* cpe:2.3:a:eclipse:jersey:3.0.16:*:*:*:*:*:*:* cpe:2.3:a:eclipse:jersey:3.1.9:*:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse jersey |
|
| Vendors & Products |
Eclipse
Eclipse jersey |
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC) | |
| Title | Race Condition allows Bypass of Trust Restrictions | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-11-18T21:34:35.027Z
Reserved: 2025-10-28T10:21:45.989Z
Link: CVE-2025-12383
Updated: 2025-11-18T21:34:32.273Z
Status : Analyzed
Published: 2025-11-18T16:15:42.867
Modified: 2026-01-16T20:09:26.027
Link: CVE-2025-12383
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:21Z
Github GHSA