Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54650

Опубликовано: 13 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-54650: nghttp2 security update (MODERATE)

[1.68.0-3.2]

  • fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libnghttp2

1.68.0-3.el10_2.2

libnghttp2-devel

1.68.0-3.el10_2.2

nghttp2

1.68.0-3.el10_2.2

Oracle Linux x86_64

libnghttp2

1.68.0-3.el10_2.2

libnghttp2-devel

1.68.0-3.el10_2.2

nghttp2

1.68.0-3.el10_2.2

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
3 месяца назад

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

CVSS3: 5.4
redhat
3 месяца назад

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

CVSS3: 5.4
nvd
3 месяца назад

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

msrc
3 месяца назад

nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length

CVSS3: 5.4
debian
3 месяца назад

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade re ...