CVE-2026-19203

Source
https://cve.org/CVERecord?id=CVE-2026-19203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19203
Aliases
  • GHSA-xc35-c22g-239h
Downstream
Published
2026-09-08T12:08:37Z
Modified
2026-09-09T03:47:13Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling.

This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.

Database specific
{
    "cna_assigner": "eclipse",
    "cwe_ids": [
        "CWE-444"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19203.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "11.0.0"
                },
                {
                    "last_affected": "11.0.31"
                },
                {
                    "introduced": "10.0.0"
                },
                {
                    "last_affected": "10.0.31"
                },
                {
                    "introduced": "9.4.0"
                },
                {
                    "last_affected": "9.4.63"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/jetty/jetty.project

Affected ranges

Type
GIT
Repo
https://github.com/jetty/jetty.project
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "12.1.0"
        },
        {
            "last_affected": "12.1.11"
        },
        {
            "introduced": "12.0.0"
        },
        {
            "last_affected": "12.0.37"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

jetty-12.*
jetty-12.0.0x
jetty-12.0.14
jetty-12.0.15
jetty-12.0.19
jetty-12.0.22
jetty-12.0.23
jetty-12.0.30
jetty-12.0.31
jetty-12.0.37
jetty-12.0.5
jetty-12.0.6
jetty-12.1.0.beta1
jetty-12.1.11
jetty-12.1.2
jetty-12.1.4
jetty-12.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19203.json"