Package
kafka-3.7
Component
jetty-http
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The jetty-http 9.4.56.v20240826 dependency is vulnerable to GHSA-355h-qmc2-wpwf (CVE-2026-2332, HTTP Request Smuggling via Chunked Extension Quoted-String Parsing). The advisory names 9.4.60 as the first patched release on the 9.4.x branch, but this version has not yet been published by upstream — the most recent 9.4.x release on jetty/jetty.project is jetty-9.4.58.v20250814. Remediation is blocked until Jetty publishes 9.4.60.
Status