THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-2332 (HIGH 7.4) — In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term

[NVD] CVE-2026-2332 (HIGH 7.4) — In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term

lownvdPublished 2026-04-14

CVE-2026-2332 CVSS: 7.4 HIGH Published: 2026-04-14T12:16:21.333

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html

* https://w4ke.info/2025/10/29/funky-chunks-2.html

Jetty terminates chunk extension parsing at \r\n inside quoted st

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-2332