Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:4029-1

Опубликовано: 07 сент. 2026
Источник: suse-cvrf

Описание

Security update for nghttp2

This update for nghttp2 fixes the following issue:

  • CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.25
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.25-openssl
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.26
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/node:22
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/openjdk:17
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/openjdk:21
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/openjdk:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/python:3
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/python:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/ruby:2
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/ruby:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/rust:1.97
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/rust:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container bci/spack:latest
libnghttp2-14-1.64.0-150700.3.6.1
libnghttp2-devel-1.64.0-150700.3.6.1
Container private-registry/1.2/harbor-trivy-adapter:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container private-registry/harbor-trivy-adapter:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/kea:2.6
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/kiosk/firefox-esr:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/postgres:16
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/postgres:16.15
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/postgres:17
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/postgres:17.11
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/postgres:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/rmt-server:latest
libnghttp2-14-1.64.0-150700.3.6.1
Container suse/sle15:latest
libnghttp2-14-1.64.0-150700.3.6.1
Image SLES15-SP7-SAPCAL-Azure
libnghttp2-14-1.64.0-150700.3.6.1
libnghttp2-14-32bit-1.64.0-150700.3.6.1
libnghttp2-devel-1.64.0-150700.3.6.1
Image SLES15-SP7-SAPCAL-EC2
libnghttp2-14-1.64.0-150700.3.6.1
libnghttp2-14-32bit-1.64.0-150700.3.6.1
libnghttp2-devel-1.64.0-150700.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libnghttp2-14-1.64.0-150700.3.6.1
libnghttp2-14-32bit-1.64.0-150700.3.6.1
libnghttp2-devel-1.64.0-150700.3.6.1

Описание

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.25-openssl:libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.25:libnghttp2-14-1.64.0-150700.3.6.1
Container bci/golang:1.26:libnghttp2-14-1.64.0-150700.3.6.1

Ссылки