CVE-2026-2332: Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- Request Smuggling: Attacker injects arbitrary HTTP requests
- Cache Poisoning: Smuggled responses poison shared caches
- Access Control Bypass: Smuggled requests bypass frontend security
- Session Hijacking: Smuggled requests can steal other users’ responses
References
Code Behaviors & Features
Detect and mitigate CVE-2026-2332 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →