CVE-2026-19203

NameCVE-2026-19203
DescriptionA client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jetty12 (PTS)trixie (security), trixie12.0.17-3.1~deb13u1vulnerable
forky12.0.33-1vulnerable
sid12.0.39-1fixed
jetty9 (PTS)bookworm, bookworm (security)9.4.57-1.1~deb12u1vulnerable
trixie (security), trixie9.4.57-1.1~deb13u1vulnerable
forky, sid9.4.58-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jetty12source(unstable)12.0.39-1
jetty9source(unstable)(unfixed)

Notes

https://github.com/jetty/jetty.project/security/advisories/GHSA-xc35-c22g-239h

Search for package or bug name: Reporting problems