THREAT OPS › Threat News › [NVD] CVE-2026-2332 (HIGH 7.4) — In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html
* https://w4ke.info/2025/10/29/funky-chunks-2.html
Jetty term
[NVD] CVE-2026-2332 (HIGH 7.4) — In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term
CVE-2026-2332 CVSS: 7.4 HIGH Published: 2026-04-14T12:16:21.333
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html
* https://w4ke.info/2025/10/29/funky-chunks-2.html
Jetty terminates chunk extension parsing at \r\n inside quoted st
Indicators of compromise
- CVE-2026-2332cve
- https://w4ke.info/2025/06/18/funky-chunks.htmlurl
- https://w4ke.info/2025/10/29/funky-chunks-2.htmlurl
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-2332