CVE-2026-12606: Medium severity Eclipse Grizzly vulnerability
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Grizzlyto a version that resolves this vulnerability.Fixed in 5.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12606?
CVE-2026-12606 has a medium severity rating of 6.3.
How does CVE-2026-12606 affect Eclipse Grizzly?
CVE-2026-12606 allows for improper parsing of trailer headers, leading to potential HTTP request smuggling.
Which versions of Eclipse Grizzly are impacted by CVE-2026-12606?
Eclipse Grizzly versions before 5.0.2 are impacted by CVE-2026-12606.
How can I mitigate the risks associated with CVE-2026-12606?
To mitigate the risks of CVE-2026-12606, upgrade to Eclipse Grizzly version 5.0.2 or later.
What is HTTP request smuggling in the context of CVE-2026-12606?
HTTP request smuggling in the context of CVE-2026-12606 occurs when malformed trailer headers are used to confuse servers about the boundaries of HTTP messages.