CVE-2026-2332

CRITICAL CVSS 3.1: 9.1 EPSS 1.31%
Updated Sep 03, 2026
Jetty
Parameter Value
CVSS 9.1 (CRITICAL)
Affected Versions 10.0.0 — 9.4.60
Fixed In 9.4.60
Type CWE-444
Vendor Jetty
Public PoC No

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 5

Configuration From (including) Up to (excluding)
Eclipse Jetty
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
9.4.0 9.4.60
Eclipse Jetty
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
10.0.0 10.0.28
Eclipse Jetty
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
11.0.0 11.0.28
Eclipse Jetty
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
12.0.0 12.0.33
Eclipse Jetty
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
12.1.0 12.1.7

References 27

https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf
emo@eclipse.org
https://gitlab.eclipse.org/security/cve-assignment/-/issues/89
emo@eclipse.org
https://access.redhat.com/errata/RHSA-2026:10175
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:14272
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:17668
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:20568
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:21773
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22453
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:25089
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-2332
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2458187
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50221
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50222
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50223
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50263
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60239
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60246
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60247
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60250
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60251
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60254
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60259
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60248
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60249
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60252
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60256
0b0ca135-0b70-47e7-9f44-1890c2a1c46c