-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Highest
-
Affects Version/s: 7.4.0, 7.13.0, 7.19.0, 8.5.0, 8.9.0, 8.9.1, 8.9.2, 8.9.3, 8.9.4, 9.1.0, 9.0.1, 8.9.5, 9.0.2, 9.0.3, 8.9.6, 8.9.7, 9.1.1, 8.9.8, 9.2.0, 9.2.1, 9.4.0, 9.3.1, 9.2.2, 9.3.2, 9.2.3, 9.4.1, 9.2.4, 9.2.5, 9.2.6, 9.5.1, 9.5.2, 9.5.3, 9.2.7, 10.1.0, 9.2.8, 10.0.2, 10.0.3, 9.5.4, 9.2.9, 10.1.1, 10.2.0, 9.2.10, 10.1.2, 9.2.11, 9.2.12, 10.2.1, 9.2.13, 10.2.2, 9.2.14, 10.2.3, 9.2.15, 10.2.6, 9.2.17, 10.2.7, 9.2.19, 10.2.10, 10.2.11, 9.2.20, 9.2.21
-
Component/s: None
-
9.1
-
Critical
-
CVE-2026-2332
-
Atlassian (Internal)
-
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
-
Confluence Data Center
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This High severity HTTP Request Smuggling vulnerability known as CVE-2026-2332 was introduced in version 7.4.0, 7.13.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0.
This HTTP Request Smuggling vulnerability, with a CVSS Score of 7.4 and a CVSS Vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N allows an unauthenticated attacker to potentially smuggle HTTP requests via the Eclipse Jetty HTTP/1.1 chunked extension quoted-string parser, which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires no user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.22
Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13
See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes.html). You can download the latest version of Confluence Data Center and Server from the Confluence Server Download Archives | Atlassian.
The National Vulnerability Database provides the following description for this vulnerability:
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here and here. Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.