high2026-09-08SAP Commerce Cloud — Search and NavigationCVE-2026-2332

HTTP Request Smuggling via Bundled Jetty Component

SAP Commerce Cloud

Our Take

Third-party component (Jetty) vulnerability surfacing inside SAP Commerce Cloud. HTTP request smuggling can bypass WAFs and CDN security controls, making attacks appear to originate from the proxy layer. Commerce Cloud Search and Navigation is customer-facing in most implementations, which raises real-world exposure.

Vulnerability Detail

Bundled Jetty HTTP server component incorrectly handles chunk extension parsing, enabling HTTP request smuggling between the front-end proxy and the Jetty back-end. Allows an attacker to poison shared connection caches or bypass security controls.

Patch Action

Apply the patch per SAP Note 3791068 to update the bundled Jetty component in SAP Commerce Cloud Search and Navigation.

Patch Info

CVSS Score

7.4

SAP Note

3791068

CVE

CVE-2026-2332

Published

2026-09-08

← All patches