Vulnerability CVE-2026-2332 in PAM A2A Client Jetty Library
search cancel

Vulnerability CVE-2026-2332 in PAM A2A Client Jetty Library

book

Article ID: 446666

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Security scanners (such as Qualys or Nessus) flag the following library in the PAM A2A client installation directory as vulnerable to CVE-2026-2332:

/opt/Broadcom/PAM/A2A/cspmclient_v.4.12.3/lib/jetty-all-9.4.54.v20240208-uber.jar

Environment

  • Product: Broadcom Privileged Access Manager (PAM)
  • Component: A2A (Application-to-Application) Client
  • Versions: 4.12.3 and earlier versions utilizing Jetty 9.4.x

Cause

CVE-2026-2332 affects Eclipse Jetty versions up to 9.4.59. The vulnerability involves the parsing of chunked transfer encoding in HTTP/1.1 requests. Security scanners identify the library based on its version string and the presence of the .jar file in the file system.

Resolution

Broadcom Engineering has evaluated the impact of CVE-2026-2332 on the PAM A2A client and determined the following:

  • Non-Exploitable: The A2A client operates strictly as an outbound agent. It does not function as an externally accessible HTTP server.
  • Architecture: The client does not expose a network-facing interface that would allow an external attacker to invoke the vulnerable HTTP/1.1 request parsing logic.
  • Status: While the library is present, the conditions required to exploit the vulnerability are not met in the A2A client architecture. This finding can be treated as a False Positive for risk assessment purposes.

Broadcom is committed to maintaining a clean security profile and will update the embedded third-party library in our upcoming release.

  • Fix Version: The Jetty library will be upgraded to a non-vulnerable version in PAM release 4.3.2.
  • Recommendation: Customers should plan to update their A2A clients once PAM 4.3.2 is available.