PT-2026-32618 · Eclipse Foundation+1 · Jetty+1

Xclow3N

·

Published

2026-04-14

·

Updated

2026-05-01

·

CVE-2026-2332

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 12.1.0 through 12.1.6 Eclipse Jetty versions 12.0.0 through 12.0.32 Eclipse Jetty versions 11.0.0 through 11.0.27 Eclipse Jetty versions 10.0.0 through 10.0.27 Eclipse Jetty versions 9.4.0 through 9.4.59
Description The HTTP/1.1 parser incorrectly handles quoted strings within chunked transfer encoding extension values. Specifically, the parser terminates chunk header parsing when it encounters a carriage return and line feed (CRLF) sequence inside a quoted string instead of treating it as a parsing error. This behavior allows an attacker to inject smuggled HTTP requests, which can lead to cache poisoning, access control bypass, and session hijacking.
Recommendations Update Eclipse Jetty to a version later than 12.1.6. Update Eclipse Jetty to a version later than 12.0.32. Update Eclipse Jetty to a version later than 11.0.27. Update Eclipse Jetty to a version later than 10.0.27. Update Eclipse Jetty to a version later than 9.4.59.

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2026-2332
GHSA-355H-QMC2-WPWF
OPENSUSE-SU-2026:10574-1

Affected Products

Jetty
Rocky Linux