PT-2026-53087 · Nghttp2+4 · Nghttpx+4
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
nghttp2 nghttpx versions prior to 1.69.0
Description
The nghttpx proxy forwards HTTP/1.1 Upgrade requests that contain a
Content-Length header and body onto reusable keep-alive backend connections. During this process, it re-adds the Upgrade and Connection headers while passing the Content-Length verbatim. If a backend resolves this ambiguous message in favor of an attacker, it can lead to HTTP request/response smuggling and cross-client response-queue poisoning. There have been reports of increased actor activities targeting this issue.Recommendations
Update nghttp2 nghttpx to version 1.69.0 or later.
Exploit
Fix
DoS
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Nghttpx