Fedora Account System
Red Hat Associate
Red Hat Customer
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:20568 https://access.redhat.com/errata/RHSA-2026:20568
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 Via RHSA-2026:22453 https://access.redhat.com/errata/RHSA-2026:22453
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:50222 https://access.redhat.com/errata/RHSA-2026:50222
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:50223 https://access.redhat.com/errata/RHSA-2026:50223
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:50263 https://access.redhat.com/errata/RHSA-2026:50263