Bug 2458187 (CVE-2026-2332)
| Summary: | CVE-2026-2332 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | abrianik, anthomas, anujha, aprice, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, caswilli, ccranfor, chfoley, crizzo, csutherl, dbruscin, dfreiber, dhanak, dlofthou, drichtar, drosa, drow, dsoumis, ehelms, ehugonne, ewittman, fmariani, fmongiar, gbenhaim, ggainey, ggrzybek, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jburrell, jclere, jnethert, jpasqual, jpechane, jraez, jrokos, jsamir, juwatts, jwon, kaycoth, kgaikwad, kvanderr, mcarlett, mdellweg, mhulan, mnovotny, mosmerov, mposolda, mstipich, msvehla, nipatil, niyer, nmoumoul, nwallace, oezr, osousa, pantinor, parichar, pberan, pcreech, pdelbell, pesilva, pjindal, plodge, pmackay, rchan, rexwhite, rgodfrey, rhel-process-autobot, rkubis, rmartinc, rmaucher, rstancel, rstepani, sausingh, sdawley, smaestri, smallamp, ssilvert, sthirugn, sthorger, swoodman, szappis, tasato, tcunning, thjenkin, tmalecek, twaugh, vdosoudi, vkumar, vmuzikar, watson-tool-maintainers, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Eclipse Jetty. The HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used. An attacker can inject crafted requests to manipulate and trick the parser. This issue can lead to security controls bypass, cache poisoning or unauthorized endpoint access.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2458713 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-14 12:01:29 UTC
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:20568 https://access.redhat.com/errata/RHSA-2026:20568 This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 Via RHSA-2026:22453 https://access.redhat.com/errata/RHSA-2026:22453 This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:50222 https://access.redhat.com/errata/RHSA-2026:50222 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:50223 https://access.redhat.com/errata/RHSA-2026:50223 This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:50263 https://access.redhat.com/errata/RHSA-2026:50263 |