Red Hat Security Advisory: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C. Security Fix(es): * nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
CVE-2026-58055 is a vulnerability in nghttp2's nghttpx proxy component that enables HTTP request smuggling and response-queue poisoning via ambiguous handling of HTTP/1.1 Upgrade requests containing a Content-Length header. The proxy forwards such requests to reusable keep-alive backend connections ambiguously, allowing an attacker to poison responses across clients. This flaw is rated moderate severity due to the high attack complexity required for successful exploitation. The vulnerability affects Red Hat Hardened Images RPMs including libnghttp2 version 1.69.0-3.1.hum1 on architectures aarch64 and x86_64. Red Hat recommends mitigation by configuring edge devices to drop HTTP/1.1 requests with both Upgrade and Content-Length headers. No explicit patch or official fix release is confirmed in the advisory, but updated RPMs including this fix are referenced. The CVE is associated with CWE-444 (Inconsistent Interpretation of HTTP Requests).
Potential Impact
Successful exploitation could allow an attacker to perform HTTP request smuggling and cross-client response poisoning, potentially leading to integrity and confidentiality impacts such as web cache poisoning, firewall bypass, and unauthorized access to web applications. However, exploitation requires high attack complexity and no privileges or user interaction. Availability is not impacted. The flaw affects the proxy's handling of HTTP/1.1 Upgrade requests with Content-Length headers, causing ambiguous forwarding to backend connections.
Mitigation Recommendations
Red Hat advises configuring your web application firewall (WAF) or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This mitigation blocks malformed traffic at the network edge before it reaches the vulnerable proxy, without impacting legitimate users. Users should monitor Red Hat advisories for updated RPMs and apply them when available. Patch status is not explicitly confirmed; check the vendor advisory for current remediation guidance.
Red Hat Security Advisory: nghttp2 security update
Description
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C. Security Fix(es): * nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-58055 is a vulnerability in nghttp2's nghttpx proxy component that enables HTTP request smuggling and response-queue poisoning via ambiguous handling of HTTP/1.1 Upgrade requests containing a Content-Length header. The proxy forwards such requests to reusable keep-alive backend connections ambiguously, allowing an attacker to poison responses across clients. This flaw is rated moderate severity due to the high attack complexity required for successful exploitation. The vulnerability affects Red Hat Hardened Images RPMs including libnghttp2 version 1.69.0-3.1.hum1 on architectures aarch64 and x86_64. Red Hat recommends mitigation by configuring edge devices to drop HTTP/1.1 requests with both Upgrade and Content-Length headers. No explicit patch or official fix release is confirmed in the advisory, but updated RPMs including this fix are referenced. The CVE is associated with CWE-444 (Inconsistent Interpretation of HTTP Requests).
Potential Impact
Successful exploitation could allow an attacker to perform HTTP request smuggling and cross-client response poisoning, potentially leading to integrity and confidentiality impacts such as web cache poisoning, firewall bypass, and unauthorized access to web applications. However, exploitation requires high attack complexity and no privileges or user interaction. Availability is not impacted. The flaw affects the proxy's handling of HTTP/1.1 Upgrade requests with Content-Length headers, causing ambiguous forwarding to backend connections.
Mitigation Recommendations
Red Hat advises configuring your web application firewall (WAF) or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This mitigation blocks malformed traffic at the network edge before it reaches the vulnerable proxy, without impacting legitimate users. Users should monitor Red Hat advisories for updated RPMs and apply them when available. Patch status is not explicitly confirmed; check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-58055
- Cve Count
- 1
Threat ID: 6a42ed7f27e9c7971993ea5a
Added to database: 06/29/2026, 22:11:11 UTC
Last enriched: 08/17/2026, 21:34:41 UTC
Last updated: 09/12/2026, 22:01:35 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.