Security scanners (such as Qualys or Nessus) flag the following library in the PAM A2A client installation directory as vulnerable to CVE-2026-2332:
/opt/Broadcom/PAM/A2A/cspmclient_v.4.12.3/lib/jetty-all-9.4.54.v20240208-uber.jar
CVE-2026-2332 affects Eclipse Jetty versions up to 9.4.59. The vulnerability involves the parsing of chunked transfer encoding in HTTP/1.1 requests. Security scanners identify the library based on its version string and the presence of the .jar file in the file system.
Broadcom Engineering has evaluated the impact of CVE-2026-2332 on the PAM A2A client and determined the following:
Broadcom is committed to maintaining a clean security profile and will update the embedded third-party library in our upcoming release.