StackRadar

CVE-2026-2332

High

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
1 of 1
affected package

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.7.v20170914+69 more9.4.60, 10.0.28, 11.0.29, 12.0.33+1 more236
OSV records
GHSA-355h-qmc2-wpwf

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
jetty-http@9.4.58.v20250814
9.4.60

Open the chart page →

3,199
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
9.4.60

Open the chart page →

4,303
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
9.4.60
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

10,540
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

4,547
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

2,572
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
jetty-http@9.4.20.v20190813
9.4.60

Open the chart page →

2,140
cruise-controlhelm-cruise-controlVerified publisher2.1.11 of 2See more

cruise-control helm-cruise-control 2.1.1

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-http@9.4.56.v20240826
9.4.60

Open the chart page →

1,453
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jetty-http@10.0.22
10.0.28

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.62 of 4See more

druid helmforge 1.3.6

2 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
jetty-http@9.4.43.v20210629
9.4.60
library/zookeeper:3.9.5f258365d4882
jetty-http@9.4.58.v20250814
9.4.60

Open the chart page →

8,541
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
jetty-http@9.4.58.v20250814
9.4.60

Open the chart page →

3,103
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

1,449
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
jetty-http@11.0.26
11.0.29

Open the chart page →

26,612
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jetty-http@9.4.40.v20210413
9.4.60

Open the chart page →

20,650
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

7,862
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
jetty-http@9.4.11.v20180605
9.4.60

Open the chart page →

8,221
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
jetty-http@9.4.51.v20230217
9.4.60
library/zookeeper:3.8-temurin55d1e5b2e601
jetty-http@9.4.51.v20230217
9.4.60

Open the chart page →

37,671
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
jetty-http@9.4.54.v20240208
9.4.60

Open the chart page →

5,320
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
jetty-http@12.0.11
12.0.33

Open the chart page →

1,262
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

1,754
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
library/zookeeper:3.5.5b7a76ec06f68
jetty-http@9.4.17.v20190418
9.4.60

Open the chart page →

10,777
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jetty-http@9.4.44.v20210927
9.4.60

Open the chart page →

2,653
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
thehiveproject/cortex:3.1.7f4bc64fb8844
jetty-http@9.4.39.v20210325
9.4.60

Open the chart page →

6,122
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jetty-http@9.4.54.v20240208
9.4.60

Open the chart page →

45,239
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
jetty-http@9.4.5.v20170502
9.4.60

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
9.4.60

Open the chart page →

12,856
spring-boot-chartjhidalgo3-githubVerified publisher4.0.01 of 1See more

spring-boot-chart jhidalgo3-github 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
jhidalgo3/spring-echo-example:lateste08733191ea0
jetty-http@9.4.35.v20201120
9.4.60

Open the chart page →

1,703
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
jetty-http@10.0.20
10.0.28

Open the chart page →

63,461
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

444
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat56490ac14a31
jetty-http@10.0.26
10.0.28

Open the chart page →

1,595
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
jetty-http@9.4.49.v20220914
9.4.60

Open the chart page →

12,527
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
jetty-http@9.4.24.v20191120
9.4.60

Open the chart page →

6,696
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
9.4.60

Open the chart page →

4,098
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
jetty-http@9.4.36.v20210114
9.4.60

Open the chart page →

3,833
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
jetty-http@9.4.30.v20200611
9.4.60

Open the chart page →

2,427
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jetty-http@9.4.33.v20201020
9.4.60

Open the chart page →

2,391
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jetty-http@11.0.24
11.0.29

Open the chart page →

2,589
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
jetty-http@9.4.57.v20241219
9.4.60

Open the chart page →

1,494
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
jetty-http@9.4.43.v20210629
9.4.60

Open the chart page →

12,847
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-http@9.4.10.v20180503
9.4.60

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

43,341
verapdfmlohrVerified publisher1.4.01 of 1See more

verapdf mlohr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
verapdf/rest:v1.30.2341359ac6af5
jetty-http@10.0.26
10.0.28

Open the chart page →

492
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jetty-http@9.4.48.v20220622
9.4.60

Open the chart page →

12,108
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jetty-http@9.4.43.v20210629
9.4.60
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
jetty-http@9.4.52.v20230823
9.4.60

Open the chart page →

16,198

Container images carrying it

236 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
trinodb/trino:4815b5e0a97f599
jetty-http@11.0.26
11.0.29
1
trinodb/trino:4796af989b0846d
jetty-http@11.0.26
11.0.29
1
trinodb/trino:405ee80ab5eeab2
jetty-http@9.4.49.v20220914
9.4.60
1
verapdf/rest:v1.30.2341359ac6af5
jetty-http@10.0.26
10.0.28
1
vespaengine/vespa:8.526.1569b160f58211
jetty-http@12.0.21
12.0.33
1
voltha/voltha-onos:5.1.8e038acb950d3
jetty-http@9.4.43.v20210629
9.4.60
1
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-http@9.4.27.v20200227
9.4.60
1
wistefan/mvf:lateste0887302b2d8
jetty-http@9.4.48.v20220622
9.4.60
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jetty-http@9.4.48.v20220622
9.4.60
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
jetty-http@12.0.25
12.0.33
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
9.4.60
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
9.4.60
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jetty-http@9.4.7.v20170914
9.4.60
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jetty-http@11.0.26
11.0.29
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jetty-http@9.4.7.v20170914
9.4.60
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
jetty-http@10.0.20
10.0.28
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.60
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.60
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-http@9.4.44.v20210927
9.4.60
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jetty-http@12.0.25
12.0.33
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-http@9.4.51.v20230217
9.4.60
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jetty-http@12.0.16
12.0.33
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
9.4.60
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-http@9.4.11.v20180605
9.4.60
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jetty-http@9.4.57.v20241219
9.4.60
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
9.4.60
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.