Описание
Security update for nghttp2
This update for nghttp2 fixes the following issue
- CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
libnghttp2_asio-devel-1.40.0-150600.25.8.1
libnghttp2_asio1-1.40.0-150600.25.8.1
Ссылки
- Link for SUSE-SU-2026:3153-1
- E-Mail link for SUSE-SU-2026:3153-1
- SUSE Security Ratings
- SUSE Bug 1269489
- SUSE CVE CVE-2026-58055 page
Описание
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:libnghttp2_asio-devel-1.40.0-150600.25.8.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libnghttp2_asio1-1.40.0-150600.25.8.1
Ссылки
- CVE-2026-58055
- SUSE Bug 1269489