CVE-2026-12606
published 2026-07-14CVE-2026-12606: Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.30%
22.1th percentile
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the behavior that fixes the vulnerability - set org.glassfish.grizzly.http.STRICT_HEADER_NAME_VALIDATION_RFC_9110 and org.glassfish.grizzly.http.STRICT_HEADER_VALUE_VALIDATION_RFC_9110 system properties to "true".
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | grizzly | 4.0.0 – 4.0.2 | — |
| eclipse | grizzly | >= 5.0.0 < 5.0.2 | 5.0.2 |
| eclipse_foundation | eclipse_glassfish | 4.0.0 – 4.0.2 | — |
| eclipse_foundation | eclipse_glassfish | >= 5.0.0 < 5.0.2 | 5.0.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Eclipse Grizzly up to 5.0.1 Trailer Parser request smuggling (Nessus ID 327174)
vuldb·2026-07-29·CVSS 5.3
CVE-2026-12606 [MEDIUM] Eclipse Grizzly up to 5.0.1 Trailer Parser request smuggling (Nessus ID 327174)
A vulnerability classified as problematic was found in Eclipse Grizzly up to 5.0.1. Affected by this issue is some unknown functionality of the component Trailer Parser. Executing a manipulation can lead to http request smuggling.
This vulnerability is registered as CVE-2026-12606. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
GHSA
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
ghsa_unreviewed·2026-07-14
CVE-2026-12606 [MEDIUM] CWE-444 Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published