Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21302-1

Опубликовано: 10 июл. 2026
Источник: suse-cvrf

Описание

Security update for nghttp2

This update for nghttp2 fixes the following issue

  • CVE-2026-58055: HTTP request/response smuggling via upgrade request with Content-Length (bsc#1269489).

Список пакетов

openSUSE Leap 16.0
libnghttp2-14-1.64.0-160000.4.1
libnghttp2-devel-1.64.0-160000.4.1
nghttp2-1.64.0-160000.4.1

Описание

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.


Затронутые продукты
openSUSE Leap 16.0:libnghttp2-14-1.64.0-160000.4.1
openSUSE Leap 16.0:libnghttp2-devel-1.64.0-160000.4.1
openSUSE Leap 16.0:nghttp2-1.64.0-160000.4.1

Ссылки