Red Hat released RHSA-2026:25089 for HawtIO 4.4.0 in the Red Hat build of Apache Camel 4, shipping an Important-rated security update that fixes a broad set of vulnerabilities across bundled components. The advisory covers issues in Spring Boot, axios, Jetty, Quarkus Vert.x HTTP, Vert.x Core, fast-uri, lodash-related HawtIO code, and Go libraries used by the hawtio-operator-container, with impacts ranging from remote and arbitrary code execution to authentication and authorization bypass, path traversal, prototype pollution, denial of service, certificate validation bypass, information disclosure, and session hijacking.
A key issue addressed is CVE-2026-2332, an Important-severity HTTP request smuggling flaw in Eclipse Jetty caused by improper handling of chunk extensions with an unclosed double quote before CRLF. Red Hat said a remote attacker could exploit Jetty servers deployed behind reverse proxies or load balancers to bypass security controls, poison caches, or reach unauthorized endpoints, and noted no practical mitigation beyond updating affected packages. Red Hat listed fixes across multiple products, including HawtIO, Red Hat AMQ Broker, Red Hat build of Apache Camel, Red Hat Enterprise Linux 9, and several Red Hat Satellite releases, and urged customers to apply the relevant errata.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat published its CVE page for CVE-2026-2332, describing an Important Jetty HTTP/1.1 request smuggling flaw involving malformed chunk extensions and stating no practical mitigation was identified. The page also listed HawtIO 4.4.0 as fixed in RHSA-2026:25089 and advised customers to update affected packages promptly.
Red Hat published security advisory RHSA-2026:25089 for HawtIO 4.4.0 in the Red Hat build of Apache Camel 4, rated Important. The advisory announced the GA security update and bundled fixes for numerous vulnerabilities across Spring Boot, axios, Jetty, Quarkus Vert.x HTTP, Vert.x Core, HawtIO code, and Go libraries.
Red Hat listed Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 as fixed for CVE-2026-2332 in RHSA-2026:22453. The advisory tied this product update to remediation of the Jetty request smuggling issue.
Red Hat listed Red Hat Enterprise Linux 9 with component jmc as fixed for CVE-2026-2332 in RHSA-2026:20568. This was one of the product-specific remediations for the Jetty parser flaw.
Red Hat listed Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 as fixed for CVE-2026-2332 in RHSA-2026:17668. The affected component was jetty-http.
Red Hat listed Red Hat AMQ Broker 7.13.5 as fixed for CVE-2026-2332 in security advisory RHSA-2026:14272. The fix addressed the Jetty HTTP request smuggling flaw in that product line.
Red Hat listed Red Hat Satellite 6.16, 6.17, 6.18, and 6.19 releases for RHEL 8 and 9 with openvox-server as fixed for CVE-2026-2332 through RHSA-2026:50221, RHSA-2026:50222, RHSA-2026:50223, and RHSA-2026:50263. These advisories extended remediation of the Jetty flaw to Satellite product lines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.