CVE-2009-1101: Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtim
Summary
CVE-2009-1101 is a vulnerability in Java's lightweight HTTP server (a simple web server built into Java SE Development Kit and Java Runtime Environment version 6 Update 12 and earlier) that allows remote attackers to cause a denial of service (a situation where a service becomes unavailable, in this case through resource consumption) when a connection is made without sending any data, which causes a file descriptor leak (when the system fails to release resources it allocated for that connection). The vulnerability affects JAX-WS service endpoints (web services built with Java's web services framework).
Vulnerability Details
5
EPSS: 7.2%
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2009-1101
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%