Eclipse Jersey has a Race Condition
Critical severity
GitHub Reviewed
Published
Nov 18, 2025
to the GitHub Advisory Database
•
Updated Nov 18, 2025
Package
Affected versions
< 2.46
>= 3.0.0-M1, < 3.0.17
>= 3.1.0-M1, < 3.1.10
= 4.0.0-M1
Patched versions
2.46
3.0.17
3.1.10
4.0.0-M2
Description
Published by the National Vulnerability Database
Nov 18, 2025
Published to the GitHub Advisory Database
Nov 18, 2025
Reviewed
Nov 18, 2025
Last updated
Nov 18, 2025
In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
References