CVE-2026-2332Disclosure(eclipse / jetty)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch eclipse jetty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jetty

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-15); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
jetty

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-04-19: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-28: 104-1404-1504-1904-28
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-141
Patch1
2026-04-152
Disclosure1General1
2026-04-191
Disclosure1
2026-04-281
Disclosure1
Full discourse5 posts
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-2332 | Eclipse Foundation Eclipse Jetty | Vulnerability Description Eclipse Jetty's HTTP/1.1 parser is vulnerable to request smuggling via chunk extensions in funky chunks attacks. It terminates parsing at embedded CRLF inside unclosed quoted strings instead of erroring, allowing attackers to inject a smuggled request like POST with '1;ext=val CRLF X CRLF 0 CRLF' followed by a GET. Affects the HTTP/1.1 chunked transfer encoding parser. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Eclipse Foundation Eclipse Jetty Affected Version: >= 12.1.0 and <= 12.1.6; >= 12.0.0 and <= 12.0.32; >= 11.0.0 and <= 11.0.27; >= 10.0.0 and <= 10.0.27; >= 9.4.0 and <= 9.4.59 Sources Research: https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf Research: https://gitlab.eclipse.org/security/cve-assignment/-/issues/89

    Post summary

    CVE-2026-2332 is a request-smuggling flaw in Eclipse Jetty’s HTTP/1.1 parser; a patch is available but no PoC or exploitation reports exist.

    1000166
    8 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-2332: CVE-2026-2332: HTTP Request Smuggling in Eclipse Jetty via Chunked Extension Quoted-String Parsing Eclipse Jetty's HTTP/1.1 parser contains a state-machine flaw when handling chunked transfer encoding extensions, leading to critical HTT... https://cvereports.com/reports/CVE-2026-2332

    Post summary

    The passage announces a new HTTP Request Smuggling vulnerability in Eclipse Jetty’s chunked transfer parser, offering technical details but no PoC, exploit, mitigation, or evidence of active exploitation.

    0000021
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2332 In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * ht… https://www.cve.org/CVERecord?id=CVE-2026-2332

    Post summary

    This post announces CVE‑2026‑2332 as a request smuggling flaw in Eclipse Jetty’s HTTP/1.1 parser that uses chunk extensions, providing only the vulnerability description and a link to the CVE record.

    0000085
    57.2K followersView on X
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting Eclipse Jetty (CVE-2026-2332) https://vuldb.com/vuln/357304/cti

    Post summary

    The note signals that actors are increasingly targeting Eclipse Jetty via CVE-2026-2332, but provides no technical or exploit details.

    0000061
    2.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Eclipse Jetty, HTTP Request Smuggling, #CVE-2026-2332 (Critical) https://dailycve.com/eclipse-jetty-http-request-smuggling-cve-2026-2332-critical/

    Post summary

    The text announces a new critical vulnerability (CVE‑2026‑2332) in Eclipse Jetty categorized as HTTP Request Smuggling, but provides no evidence of exploitation or mitigation steps.

    0000039
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipsejetty---

Explore more