VDB
DEBIAN-CVE-2026-2332
DEBIAN-CVE-2026-2332
PUBLISHED
CVSS 9.100000381469727 CRITICAL
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | jetty9 | 0, 9.4.57-1, 9.4.57-1.1~deb12u1 |
| Debian:11 | jetty9 | 9.4.50-3, 9.4.50-4, 9.4.50-4+deb11u1 |
| Debian:14 | jetty12 | 12.0.32-2, 12.0.32-1, 0 |
| Debian:13 | jetty12 | 0, 12.0.17-3.1, 12.0.17-3 |
| Debian:13 | jetty9 | 9.4.57-1.1, 9.4.57-1.1, 9.4.57-1.1~deb12u1 |
| Debian:12 | jetty9 | 0, 9.4.50-4+deb12u1, 9.4.50-4+deb12u2 |
Exploit Intelligence
- suppression.xml (github-poc)
- jetty-jmx_advisory.json (github-poc)
- jetty-javadoc_advisory.json (github-poc)
- 3TSoftwareLabs.Studio3T.locale.en-US.yaml (github-poc)
- dependency-check-suppress.xml (github-poc)
- cve-2026-3612.html (github-poc)
Timeline
- Apr 14, 2026 CVE Published
- May 2, 2026 CVE Updated