Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2332

36
FAUCET Score

OVERVIEW CVE-2026-2332 is an HTTP request smuggling vulnerability in Eclipse Jetty's HTTP/1.1 parser that occurs when processing chunk extensions with improperly terminated quoted strings. The vulnerability allows attackers to inject malformed chunk extensions containing unescaped carriage return/line feed sequences, which Jetty incorrectly treats as valid extension terminators rather than parsing errors. This design flaw enables attackers to inject smuggled HTTP requests that bypass security controls and filters. SEVERITY The vulnerability carries a CVSS 7.4 HIGH rating with a network-based attack vector requiring high complexity and no user interaction. The attack has significant impact on confidentiality and integrity, allowing potential data theft and request manipulation, though availability is not directly compromised. The EPSS score of 0.00014 indicates extremely low current exploitation probability compared to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. Community attention remains limited as measured by the FAUCET Risk Score of 47.0 out of 100. While proof-of-concept techniques exist in published research on "funky chunks" request smuggling methods, no weaponized exploit code appears to be publicly available or actively distributed.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.4.0, < 9.4.60CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 10.0.0, < 10.0.28CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 11.0.0, < 11.0.28CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 12.0.0, < 12.0.33CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
>= 12.1.0, < 12.1.7CPE matchmatch criteria
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.08%
Probability of exploitation in next 30 days
EPSS Percentile
61.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0109 is in the 47th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-httpFixed in: 12.1.7
mavenpatch availablevia ghsa
Product: org.eclipse.jetty:jetty-httpFixed in: 12.0.33
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

mavenGHSA-355h-qmc2-wpwfhigh

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:10175
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:20568
access.redhat.com / errata/RHSA-2026:21773
access.redhat.com / errata/RHSA-2026:22453
access.redhat.com / errata/RHSA-2026:25089
access.redhat.com / security/cve/CVE-2026-2332
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-2332.json
github.com / jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf
ExploitMitigationVendor Advisory
gitlab.eclipse.org / security/cve-assignment/-/issues/89
Issue TrackingVendor Advisory