๐Ÿ” CVE Alert

CVE-2026-19203

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.

CWE CWE-444
Vendor eclipse foundation
Product eclipse jetty
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse jetty

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse jetty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Jetty
12.1.0 โ‰ค 12.1.11 12.0.0 โ‰ค 12.0.37 11.0.0 โ‰ค 11.0.31 10.0.0 โ‰ค 10.0.31 9.4.0 โ‰ค 9.4.63

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jetty/jetty.project/security/advisories/GHSA-xc35-c22g-239h

Credits

๐Ÿ” https://github.com/yarocher