OVERVIEW CVE-2026-2332 is an HTTP request smuggling vulnerability in Eclipse Jetty's HTTP/1.1 parser that occurs when processing chunk extensions with improperly terminated quoted strings. The vulnerability allows attackers to inject malformed chunk extensions containing unescaped carriage return/line feed sequences, which Jetty incorrectly treats as valid extension terminators rather than parsing errors. This design flaw enables attackers to inject smuggled HTTP requests that bypass security controls and filters. SEVERITY The vulnerability carries a CVSS 7.4 HIGH rating with a network-based attack vector requiring high complexity and no user interaction. The attack has significant impact on confidentiality and integrity, allowing potential data theft and request manipulation, though availability is not directly compromised. The EPSS score of 0.00014 indicates extremely low current exploitation probability compared to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. Community attention remains limited as measured by the FAUCET Risk Score of 47.0 out of 100. While proof-of-concept techniques exist in published research on "funky chunks" request smuggling methods, no weaponized exploit code appears to be publicly available or actively distributed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4.0, < 9.4.60CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.28CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.28CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.0.33CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 12.1.0, < 12.1.7CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.