CVE-2026-19203: Eclipse Foundation Eclipse Jetty

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.

Affected products

  • Eclipse Foundation Eclipse Jetty: from 12.1.0, up to and including 12.1.11; from 12.0.0, up to and including 12.0.37; from 11.0.0, up to and including 11.0.31; from 10.0.0, up to and including 10.0.31; from 9.4.0, up to and including 9.4.63

Published 2026-09-08. Last modified 2026-09-08.