PT-2026-53087 · Nghttp2+4 · Nghttpx+4

·

CVE-2026-58055

·

Published

2026-05-22

·

Updated

2026-08-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions nghttp2 nghttpx versions prior to 1.69.0
Description The nghttpx proxy forwards HTTP/1.1 Upgrade requests that contain a Content-Length header and body onto reusable keep-alive backend connections. During this process, it re-adds the Upgrade and Connection headers while passing the Content-Length verbatim. If a backend resolves this ambiguous message in favor of an attacker, it can lead to HTTP request/response smuggling and cross-client response-queue poisoning. There have been reports of increased actor activities targeting this issue.
Recommendations Update nghttp2 nghttpx to version 1.69.0 or later.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54650
ALSA-2026:54662
ALSA-2026:55804
AZL-91451
BDU:2026-08977
CVE-2026-58055
ECHO-401A-73DF-0D29
JLSEC-2026-1157
OESA-2026-2977
OESA-2026-2978
OESA-2026-2979
OESA-2026-2980
OPENSUSE-SU-2026:11156-1
OPENSUSE-SU-2026:21302-1
RHSA-2026:35454
RHSA-2026:41240
RHSA-2026:52414
RHSA-2026:54650
RHSA-2026:54662
RHSA-2026:55804
SUSE-SU-2026:22594-1
SUSE-SU-2026:22630-1
SUSE-SU-2026:22707-1
SUSE-SU-2026:22893-1
SUSE-SU-2026:2883-1
SUSE-SU-2026:3153-1
SUSE-SU-2026:3154-1
USN-8495-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Nghttpx