Описание
Security update for nghttp2
This update for nghttp2 fixes the following issue
- CVE-2026-58055: HTTP request/response smuggling via upgrade request with
Content-Length(bsc#1269489).
Список пакетов
openSUSE Leap 16.0
libnghttp2-14-1.64.0-160000.4.1
libnghttp2-devel-1.64.0-160000.4.1
nghttp2-1.64.0-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1269489
- SUSE CVE CVE-2026-58055 page
Описание
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
Затронутые продукты
openSUSE Leap 16.0:libnghttp2-14-1.64.0-160000.4.1
openSUSE Leap 16.0:libnghttp2-devel-1.64.0-160000.4.1
openSUSE Leap 16.0:nghttp2-1.64.0-160000.4.1
Ссылки
- CVE-2026-58055
- SUSE Bug 1269489