PT-2026-32618 · Eclipse Foundation+1 · Jetty+1

·

CVE-2026-2332

·

Published

2026-04-14

·

Updated

2026-07-09

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 12.1.0 through 12.1.6 Eclipse Jetty versions 12.0.0 through 12.0.32 Eclipse Jetty versions 11.0.0 through 11.0.27 Eclipse Jetty versions 10.0.0 through 10.0.27 Eclipse Jetty versions 9.4.0 through 9.4.59
Description The HTTP/1.1 parser incorrectly handles quoted strings within chunked transfer encoding extension values. Specifically, the parser terminates chunk header parsing when it encounters a carriage return and line feed (CRLF) sequence inside a quoted string instead of treating it as a parsing error. This behavior allows an attacker to inject smuggled HTTP requests, which can lead to cache poisoning, access control bypass, and session hijacking.
Recommendations Update Eclipse Jetty to a version later than 12.1.6. Update Eclipse Jetty to a version later than 12.0.32. Update Eclipse Jetty to a version later than 11.0.27. Update Eclipse Jetty to a version later than 10.0.27. Update Eclipse Jetty to a version later than 9.4.59.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:20568
CLEANSTART-2026-CC73064
CLEANSTART-2026-GV99300
CLEANSTART-2026-NH93073
CLEANSTART-2026-QC20347
CLEANSTART-2026-RR82368
CLEANSTART-2026-VG07087
CVE-2026-2332
GHSA-355H-QMC2-WPWF
OPENSUSE-SU-2026:10574-1
RHSA-2026:20568
SUSE-SU-2026:1751-1

Affected Products

Jetty
Rocky Linux