CVE-2026-19203
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.
| CWE | CWE-444 |
| Vendor | eclipse foundation |
| Product | eclipse jetty |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse jetty
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse jetty are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Jetty
12.1.0 โค 12.1.11 12.0.0 โค 12.0.37 11.0.0 โค 11.0.31 10.0.0 โค 10.0.31 9.4.0 โค 9.4.63
References
Credits
๐ https://github.com/yarocher