StackRadar

CVE-2026-2332

High

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
1 of 1
affected package

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.7.v20170914+69 more9.4.60, 10.0.28, 11.0.29, 12.0.33+1 more236
OSV records
GHSA-355h-qmc2-wpwf

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jetty-http@9.4.57.v20241219
9.4.60

Open the chart page →

1,733
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jetty-http@9.4.54.v20240208
9.4.60

Open the chart page →

45,239
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
9.4.60

Open the chart page →

4,303
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.60

Open the chart page →

3,176
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-http@9.4.41.v20210516
9.4.60
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
jetty-http@9.4.51.v20230217
9.4.60

Open the chart page →

9,397
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-2332.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
jetty-http@12.0.12
12.0.33

Open the chart page →

2,634

Container images carrying it

236 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
trinodb/trino:4815b5e0a97f599
jetty-http@11.0.26
11.0.29
1
trinodb/trino:4796af989b0846d
jetty-http@11.0.26
11.0.29
1
trinodb/trino:405ee80ab5eeab2
jetty-http@9.4.49.v20220914
9.4.60
1
verapdf/rest:v1.30.2341359ac6af5
jetty-http@10.0.26
10.0.28
1
vespaengine/vespa:8.526.1569b160f58211
jetty-http@12.0.21
12.0.33
1
voltha/voltha-onos:5.1.8e038acb950d3
jetty-http@9.4.43.v20210629
9.4.60
1
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-http@9.4.27.v20200227
9.4.60
1
wistefan/mvf:lateste0887302b2d8
jetty-http@9.4.48.v20220622
9.4.60
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jetty-http@9.4.48.v20220622
9.4.60
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
jetty-http@12.0.25
12.0.33
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
9.4.60
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
9.4.60
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jetty-http@9.4.7.v20170914
9.4.60
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jetty-http@11.0.26
11.0.29
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
jetty-http@9.4.56.v20240826
9.4.60
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jetty-http@9.4.7.v20170914
9.4.60
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-http@9.4.43.v20210629
9.4.60
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
jetty-http@9.4.53.v20231009
9.4.60
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
jetty-http@10.0.20
10.0.28
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
9.4.60
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
9.4.60
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-http@9.4.44.v20210927
9.4.60
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jetty-http@12.0.25
12.0.33
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-http@9.4.51.v20230217
9.4.60
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jetty-http@12.0.16
12.0.33
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
9.4.60
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-http@9.4.11.v20180605
9.4.60
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jetty-http@9.4.57.v20241219
9.4.60
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
9.4.60
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.