← Back

CVE-2026-12606

nvd nist
Published: Jul 14, 2026Modified: Jul 14, 2026

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: emo@eclipse.org (Secondary)

Description

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.

Affected (2)

Products: Eclipse: Grizzly
1 product
Grizzly
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 4.0.0 to 4.0.2
From 5.0.0 to 5.0.2

References (1)

Timeline

No history available yet.