Description
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
Problem types
CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
Product status
12.1.0 (semver)
12.0.0 (semver)
11.0.0 (semver)
10.0.0 (semver)
9.4.0 (semver)
Credits
https://github.com/xclow3n
References
github.com/...roject/security/advisories/GHSA-355h-qmc2-wpwf
gitlab.eclipse.org/security/cve-assignment/-/issues/89