Impact
Jetty’s parsing of HTTP/1.1 chunked requests treats a lone line feed as a valid chunk terminator in several parsing stages, a behavior that diverges from the standard. An attacker can craft a request that contains a single LF character in the chunk extension, data, or trailer termination fields. When Jetty and an intermediary proxy interpret the request boundaries differently, the smuggled request is delivered partially to Jetty and partially to the downstream server, enabling a range of attacks such as injection, data exfiltration, or denial of service.
Affected Systems
Eclipse Jetty servers of unspecified versions are impacted. The advisory does not list specific version numbers, so any Jetty instance that includes the affected request parsing logic may be vulnerable.
Risk and Exploitability
The CVSS score of 8.3 classifies this vulnerability as high severity. No EPSS score is available, and the issue is not registered in CISA’s KEV catalog. The likely attack vector is an external client sending maliciously crafted HTTP/1.1 chunked requests to the Jetty server. Inferred from the description is that the attacker needs network access to the server’s HTTP interface. Once exploited, an attacker can leverage the resulting request smuggling to gain unauthorized access or bypass security controls.
OpenCVE Enrichment