StackRadar

CVE-2026-2332

High

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
1 of 1
affected package

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.7.v20170914+69 more9.4.60, 10.0.28, 11.0.29, 12.0.33+1 more236
OSV records
GHSA-355h-qmc2-wpwf

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jetty-http@9.4.57.v20241219
9.4.60

Open the chart page →

1,733
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jetty-http@9.4.54.v20240208
9.4.60

Open the chart page →

45,239
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
9.4.60

Open the chart page →

4,303
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

3,176
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-http@9.4.41.v20210516
9.4.60
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
jetty-http@9.4.51.v20230217
9.4.60

Open the chart page →

9,397
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
jetty-http@12.0.12
12.0.33

Open the chart page →

2,634

Container images carrying it

236 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apacheignite/ignite:2.7.0d7deab68b8fa
jetty-http@9.4.11.v20180605
9.4.60
1
apache/iotdb:0.11.28647309f95d1
jetty-http@9.4.24.v20191120
9.4.60
1
apache/iotdb:0.13.3-nodeafa47bf1692a
jetty-http@9.4.35.v20201120
9.4.60
1
apache/kafka:4.1.0bff074a5d005
jetty-http@12.0.22
12.0.33
1
apache/kafka:3.9.0fbc7d7c428e3
jetty-http@9.4.56.v20240826
9.4.60
1
apache/nifi-registry:1.14.0090b7f87ec7f
jetty-http@9.4.42.v20210604
9.4.60
1
apache/nifi-registry:1.27.063b8e3e40742
jetty-http@9.4.54.v20240208
9.4.60
1
apache/nifi-registry:0.8.0974efa2f21da
jetty-http@9.4.19.v20190610
9.4.60
1
apache/polaris:lateste66366e783f1
jetty-http@9.4.56.v20240826
9.4.60
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
jetty-http@9.4.51.v20230217
9.4.60
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
jetty-http@9.4.44.v20210927
9.4.60
1
apachepulsar/pulsar:2.6.14db6ff0b4045
jetty-http@9.4.29.v20200521
9.4.60
1
apachepulsar/pulsar:3.0.79c9947de139d
jetty-http@9.4.54.v20240208
9.4.60
1
apachepulsar/pulsar:2.9.0d056c89b7131
jetty-http@9.4.43.v20210629
9.4.60
1
apachepulsar/pulsar:2.8.2d538416d5afe
jetty-http@9.4.43.v20210629
9.4.60
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
jetty-http@9.4.28.v20200408
9.4.60
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jetty-http@9.4.40.v20210413
9.4.60
1
apache/tika:3.3.1.090b7fa1dc018
jetty-http@11.0.26
11.0.29
1
apache/tika:2.9.0.092d055a84e9e
jetty-http@9.4.51.v20230217
9.4.60
1
apache/tika:3.2.2.0-fullffab324253ed
jetty-http@11.0.25
11.0.29
1
apimap/api:v1.8.11ae2b3ab00177
jetty-http@9.4.49.v20220914
9.4.60
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
jetty-http@9.4.39.v20210325
9.4.60
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
jetty-http@9.4.43.v20210629
9.4.60
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
jetty-http@9.4.43.v20210629
9.4.60
1
atlassian/bitbucket:10.2.705933f2b1cfd
jetty-http@9.4.57.v20241219
9.4.60
1
atlassian/confluence-server:7.10.03b9222ab32ef
jetty-http@9.4.19.v20190610
9.4.60
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
jetty-http@9.4.51.v20230217
9.4.60
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
jetty-http@9.4.48.v20220622
9.4.60
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jetty-http@9.4.43.v20210629
9.4.60
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
jetty-http@9.4.52.v20230823
9.4.60
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
jetty-http@9.4.49.v20220914
9.4.60
1
bivas/presto:0.19605545994f806
jetty-http@9.4.8.v20171121
9.4.60
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jetty-http@10.0.22
10.0.28
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jetty-http@11.0.20
11.0.29
1
codetogether/codetogether:latest4348c8a38752
jetty-http@9.4.55.v20240627
9.4.60
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jetty-http@9.4.51.v20230217
9.4.60
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jetty-http@9.4.33.v20201020
9.4.60
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jetty-http@9.4.33.v20201020
9.4.60
1
confluentinc/cp-kafka:5.4.01bbda887bc53
jetty-http@9.4.20.v20190813
9.4.60
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jetty-http@9.4.44.v20210927
9.4.60
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
jetty-http@9.4.57.v20241219
9.4.60
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jetty-http@9.4.56.v20240826
9.4.60
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jetty-http@9.4.53.v20231009
9.4.60
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jetty-http@9.4.11.v20180605
9.4.60
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jetty-http@9.4.51.v20230217
9.4.60
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jetty-http@9.4.33.v20201020
9.4.60
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jetty-http@9.4.33.v20201020
9.4.60
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jetty-http@9.4.53.v20231009
9.4.60
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jetty-http@9.4.33.v20201020
9.4.60
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jetty-http@9.4.33.v20201020
9.4.60
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.