{"id":"SUSE-SU-2026:1751-1","summary":"Security update for jetty-minimal","details":"This update for jetty-minimal fixes the following issues:\n\n- CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the 'funky chunks' techniques (bsc#1262115).\n- CVE-2026-5795: Fixed JaspiAuthenticator broken access control (bsc#1261997).\n","modified":"2026-05-08T08:15:27.060649Z","published":"2026-05-07T11:53:44Z","related":["CVE-2026-2332","CVE-2026-5795"],"upstream":["CVE-2026-2332","CVE-2026-5795"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261751-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261997"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5795"}],"schema_version":"1.7.5"}