{"id":"CVE-2026-2332","title":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/…","summary":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-444"],"vendor":"eclipse","product":"jetty","affected":["jetty >= 9.4.0, < 9.4.60","jetty >= 10.0.0, < 10.0.28","jetty >= 11.0.0, < 11.0.28","jetty >= 12.0.0, < 12.0.33","jetty >= 12.1.0, < 12.1.7"],"patched":["jetty 12.1.7"],"published":"2026-04-14","updated":"2026-09-10","sourceUpdated":"2026-09-10T13:18:03.987","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","references":[{"url":"https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","label":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","label":"emo@eclipse.org"},{"url":"https://access.redhat.com/errata/RHSA-2026:10175","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14272","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17668","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20568","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21773","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22453","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25089","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50221","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50222","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50223","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:50263","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60239","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60246","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60247","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60248","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60249","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60250","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60251","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60252","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60254","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60256","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60259","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-2332","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458187","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-2332"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-04-14T00:00:00+00:00"},"epss":0.01305,"epssPercentile":0.68804,"ingestedAt":"2026-07-02T12:34:40.520Z","exploits":{"github":1,"githubRepos":["https://github.com/xiaoqiMikko/jetty-line-check"],"checkedAt":"2026-09-21T15:28:29.845Z"},"slug":"CVE-2026-2332","body":"## Overview\n\nIn Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.\n\n## Affected\n\n- `jetty >= 9.4.0, < 9.4.60`\n- `jetty >= 10.0.0, < 10.0.28`\n- `jetty >= 11.0.0, < 11.0.28`\n- `jetty >= 12.0.0, < 12.0.33`\n- `jetty >= 12.1.0, < 12.1.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jetty 12.1.7`\n\n## Vendor advisories\n\n- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)\n- **RHSA-2026:50222** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50222)\n- **RHSA-2026:50263** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50263)\n- **RHSA-2026:50221** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50221)\n- **RHSA-2026:20568** · Red Hat · fixed in: Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20568)\n- **RHSA-2026:25089** · Red Hat · fixed in: HawtIO HawtIO 4.4.0 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:25089)\n- **RHSA-2026:60247** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.12 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60247)\n- **RHSA-2026:60249** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60249)\n- **RHSA-2026:60248** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60248)\n- **RHSA-2026:60239** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60239)\n- **RHSA-2026:60251** · Red Hat · fixed in: OpenShift Developer Tools and Services 4.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60251)\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat AMQ Broker 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 2, Red Hat build of Debezium 3, Red Hat Fuse 7, … · no fix planned: Red Hat build of Debezium 2, Red Hat build of Debezium 3, Red Hat Fuse 7, Red Hat JBoss Web Server 6, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":201479,"id":"CVE-2026-2332","ts":1789399491123,"field":"exploit_available","old":"false","new":"true"},{"seq":200213,"id":"CVE-2026-2332","ts":1789397046408,"field":"exploit_available","old":"true","new":"false"},{"seq":198137,"id":"CVE-2026-2332","ts":1789391718383,"field":"exploit_available","old":"false","new":"true"},{"seq":195930,"id":"CVE-2026-2332","ts":1789383378492,"field":"exploit_available","old":"true","new":"false"},{"seq":194859,"id":"CVE-2026-2332","ts":1789380295585,"field":"exploit_available","old":"false","new":"true"},{"seq":193646,"id":"CVE-2026-2332","ts":1789378243961,"field":"exploit_available","old":"true","new":"false"},{"seq":192433,"id":"CVE-2026-2332","ts":1789376216124,"field":"exploit_available","old":"false","new":"true"},{"seq":191220,"id":"CVE-2026-2332","ts":1789373104408,"field":"exploit_available","old":"true","new":"false"},{"seq":190005,"id":"CVE-2026-2332","ts":1789369116677,"field":"exploit_available","old":"false","new":"true"},{"seq":188792,"id":"CVE-2026-2332","ts":1789368031303,"field":"exploit_available","old":"true","new":"false"},{"seq":187575,"id":"CVE-2026-2332","ts":1789364985237,"field":"exploit_available","old":"false","new":"true"},{"seq":186362,"id":"CVE-2026-2332","ts":1789362971945,"field":"exploit_available","old":"true","new":"false"},{"seq":185148,"id":"CVE-2026-2332","ts":1789360954644,"field":"exploit_available","old":"false","new":"true"},{"seq":183935,"id":"CVE-2026-2332","ts":1789357911084,"field":"exploit_available","old":"true","new":"false"},{"seq":182187,"id":"CVE-2026-2332","ts":1789354079168,"field":"exploit_available","old":"false","new":"true"},{"seq":180980,"id":"CVE-2026-2332","ts":1789352929863,"field":"exploit_available","old":"true","new":"false"},{"seq":179773,"id":"CVE-2026-2332","ts":1789349979370,"field":"exploit_available","old":"false","new":"true"},{"seq":178566,"id":"CVE-2026-2332","ts":1789347775279,"field":"exploit_available","old":"true","new":"false"},{"seq":177359,"id":"CVE-2026-2332","ts":1789346164214,"field":"exploit_available","old":"false","new":"true"},{"seq":176152,"id":"CVE-2026-2332","ts":1789342718225,"field":"exploit_available","old":"true","new":"false"},{"seq":175936,"id":"CVE-2026-2332","ts":1789342330153,"field":"exploit_available","old":"false","new":"true"},{"seq":175476,"id":"CVE-2026-2332","ts":1789338370828,"field":"exploit_available","old":"true","new":"false"},{"seq":174271,"id":"CVE-2026-2332","ts":1789334585092,"field":"exploit_available","old":"false","new":"true"},{"seq":173066,"id":"CVE-2026-2332","ts":1789333192452,"field":"exploit_available","old":"true","new":"false"},{"seq":171880,"id":"CVE-2026-2332","ts":1789330871596,"field":"exploit_available","old":"false","new":"true"},{"seq":170694,"id":"CVE-2026-2332","ts":1789328374688,"field":"exploit_available","old":"true","new":"false"},{"seq":169489,"id":"CVE-2026-2332","ts":1789326891990,"field":"exploit_available","old":"false","new":"true"},{"seq":168284,"id":"CVE-2026-2332","ts":1789323412731,"field":"exploit_available","old":"true","new":"false"},{"seq":167079,"id":"CVE-2026-2332","ts":1789319357659,"field":"exploit_available","old":"false","new":"true"},{"seq":165874,"id":"CVE-2026-2332","ts":1789318254070,"field":"exploit_available","old":"true","new":"false"},{"seq":164669,"id":"CVE-2026-2332","ts":1789315524948,"field":"exploit_available","old":"false","new":"true"},{"seq":163464,"id":"CVE-2026-2332","ts":1789313241435,"field":"exploit_available","old":"true","new":"false"},{"seq":162259,"id":"CVE-2026-2332","ts":1789311703615,"field":"exploit_available","old":"false","new":"true"},{"seq":161054,"id":"CVE-2026-2332","ts":1789308245892,"field":"exploit_available","old":"true","new":"false"},{"seq":160559,"id":"CVE-2026-2332","ts":1789304171839,"field":"exploit_available","old":"false","new":"true"},{"seq":158397,"id":"CVE-2026-2332","ts":1789299257416,"field":"exploit_available","old":"true","new":"false"},{"seq":157361,"id":"CVE-2026-2332","ts":1789296451866,"field":"exploit_available","old":"false","new":"true"},{"seq":156156,"id":"CVE-2026-2332","ts":1789294360712,"field":"exploit_available","old":"true","new":"false"},{"seq":154951,"id":"CVE-2026-2332","ts":1789292626610,"field":"exploit_available","old":"false","new":"true"},{"seq":153746,"id":"CVE-2026-2332","ts":1789289332797,"field":"exploit_available","old":"true","new":"false"},{"seq":152958,"id":"CVE-2026-2332","ts":1789285235613,"field":"exploit_available","old":"false","new":"true"},{"seq":152202,"id":"CVE-2026-2332","ts":1789280950266,"field":"exploit_available","old":"true","new":"false"},{"seq":151163,"id":"CVE-2026-2332","ts":1789277445652,"field":"exploit_available","old":"false","new":"true"},{"seq":150129,"id":"CVE-2026-2332","ts":1789275891505,"field":"exploit_available","old":"true","new":"false"},{"seq":149096,"id":"CVE-2026-2332","ts":1789273611138,"field":"exploit_available","old":"false","new":"true"},{"seq":147892,"id":"CVE-2026-2332","ts":1789270866173,"field":"exploit_available","old":"true","new":"false"},{"seq":145932,"id":"CVE-2026-2332","ts":1789269170278,"field":"exploit_available","old":"false","new":"true"},{"seq":144835,"id":"CVE-2026-2332","ts":1789266101229,"field":"exploit_available","old":"true","new":"false"},{"seq":143739,"id":"CVE-2026-2332","ts":1789262433990,"field":"exploit_available","old":"false","new":"true"},{"seq":142575,"id":"CVE-2026-2332","ts":1789261172977,"field":"exploit_available","old":"true","new":"false"}]}