StackRadar

CVE-2026-2332

High

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
1 of 1
affected package

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.7.v20170914+69 more9.4.60, 10.0.28, 11.0.29, 12.0.33+1 more236
OSV records
GHSA-355h-qmc2-wpwf

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jetty-http@9.4.57.v20241219
9.4.60

Open the chart page →

1,733
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jetty-http@9.4.54.v20240208
9.4.60

Open the chart page →

45,239
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
9.4.60

Open the chart page →

4,303
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

3,176
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-http@9.4.41.v20210516
9.4.60
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
jetty-http@9.4.51.v20230217
9.4.60

Open the chart page →

9,397
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
jetty-http@12.0.12
12.0.33

Open the chart page →

2,634

Container images carrying it

236 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kafkakraft/kafka-controller:3.7.0f261ad288fce
jetty-http@9.4.53.v20231009
9.4.60
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
jetty-http@9.4.53.v20231009
9.4.60
1
keyfactor/signserver-ce:7.3.2798fbbe00283
jetty-http@9.4.8.v20171121
9.4.60
1
kyso/imagebox:latest68091eace89c
jetty-http@9.4.36.v20210114
9.4.60
1
library/couchdb:3.4.22817ad50b5c5
jetty-http@11.0.23
11.0.29
1
library/neo4j:4.2.4348e3f56faa2
jetty-http@9.4.38.v20210224
9.4.60
1
library/neo4j:2026.02.25ab4ab0358cf
jetty-http@12.0.25
12.0.33
1
library/neo4j:5.18.18f01f7bb053e
jetty-http@10.0.20
10.0.28
1
library/neo4j:3.4.5-enterprisea1ba477fa412
jetty-http@9.4.11.v20180605
9.4.60
1
library/solr:8.7.0d124efd81fbb
jetty-http@9.4.27.v20200227
9.4.60
1
library/storm:2.4.0bd5d420506d6
jetty-http@9.4.14.v20181114
9.4.60
1
library/xwiki:lts-postgres-tomcat56490ac14a31
jetty-http@10.0.26
10.0.28
1
library/zookeeper:3.6.24c8a6d3b2338
jetty-http@9.4.24.v20191120
9.4.60
1
library/zookeeper:3.8-temurin55d1e5b2e601
jetty-http@9.4.51.v20230217
9.4.60
1
library/zookeeper:3.9.5cab8944a33a1
jetty-http@9.4.58.v20250814
9.4.60
1
library/zookeeper:3.9.4dfa9ba46d14b
jetty-http@9.4.57.v20241219
9.4.60
1
localstack/localstack:3.19d278167f2b7
jetty-http@9.4.53.v20231009
9.4.60
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jetty-http@9.4.33.v20201020
9.4.60
1
merlos/zookeeper:3.9.3a38fc7e09ed7
jetty-http@9.4.56.v20240826
9.4.60
1
metabase/metabase:v0.53.4.17807bc5cad17
jetty-http@11.0.24
11.0.29
1
metabase/metabase:v0.46.09ebdc664a6b2
jetty-http@11.0.14
11.0.29
1
metabase/metabase:v0.31.2ffb2dccacefc
jetty-http@9.4.11.v20180605
9.4.60
1
microcks/microcks:0.8.0e3a3e0c67b09
jetty-http@9.4.12.v20180830
9.4.60
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jetty-http@9.4.12.v20180830
9.4.60
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jetty-http@10.0.24
10.0.28
1
onosproject/onos:2.2.144914a8d4b3f
jetty-http@9.4.22.v20191022
9.4.60
1
openhab/openhab:5.2.1bfd4a60e90da
jetty-http@9.4.58.v20250814
9.4.60
1
openhab/openhab:3.2.0d0aa4af452c1
jetty-http@9.4.43.v20210629
9.4.60
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
jetty-http@9.4.53.v20231009
9.4.60
1
owasp/dependency-track:3.8.0efc65e702ee1
jetty-http@9.4.27.v20200227
9.4.60
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
jetty-http@12.1.6
12.1.7
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
jetty-http@11.0.22
11.0.29
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.8.0fc4b9b9f5e15
jetty-http@9.4.15.v20190215
9.4.60
1
radondb/zookeeper:3.6.216981604f1a0
jetty-http@9.4.24.v20191120
9.4.60
1
resurfaceio/resurface:3.7.84d5cda2f64109
jetty-http@12.0.16
12.0.33
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
jetty-http@9.4.49.v20220914
9.4.60
1
rodolpheche/wiremock:2.27.22328a9fce2bf
jetty-http@9.4.30.v20200611
9.4.60
1
rundeck/rundeck:3.2.74d64fe56f767
jetty-http@9.4.20.v20190813
9.4.60
1
rundeck/rundeck:3.0.16b13e8059ad72
jetty-http@9.4.11.v20180605
9.4.60
1
scmmanager/scm-manager:3.12.1bfb766050f34
jetty-http@11.0.26
11.0.29
1
sismics/docs:v1.10f4b0ef019cf1
jetty-http@9.4.36.v20210114
9.4.60
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
jetty-http@12.0.15
12.0.33
1
sonatype/nexus3:3.58.1586060431b64
jetty-http@9.4.51.v20230217
9.4.60
1
stain/jena-fuseki:latestb1d0c96f19ad
jetty-http@12.0.11
12.0.33
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-http@9.4.48.v20220622
9.4.60
1
thehiveproject/cortex:3.1.7f4bc64fb8844
jetty-http@9.4.39.v20210325
9.4.60
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-http@9.4.6.v20170531
9.4.60
1
traccar/traccar:6.7-alpine621c8d6d46fd
jetty-http@11.0.25
11.0.29
1
trinodb/trino:4801565e8cac299
jetty-http@11.0.26
11.0.29
1
trinodb/trino:45038c6f24ab1a4
jetty-http@12.0.9
12.0.33
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.