Количество 19
Количество 19
CVE-2026-58055
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
CVE-2026-58055
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
CVE-2026-58055
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
CVE-2026-58055
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVE-2026-58055
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade re ...
openSUSE-SU-2026:21302-1
Security update for nghttp2
SUSE-SU-2026:4029-1
Security update for nghttp2
SUSE-SU-2026:3154-1
Security update for nghttp2
SUSE-SU-2026:3153-1
Security update for nghttp2
RLSA-2026:55804
Moderate: nghttp2 security update
RLSA-2026:54662
Moderate: nghttp2 security update
RLSA-2026:54650
Moderate: nghttp2 security update
GHSA-xrr7-82jr-v58x
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
ELSA-2026-55804
ELSA-2026-55804: nghttp2 security update (MODERATE)
ELSA-2026-54662
ELSA-2026-54662: nghttp2 security update (MODERATE)
ELSA-2026-54650
ELSA-2026-54650: nghttp2 security update (MODERATE)
BDU:2026-08977
Уязвимость компонента nghttpx библиотеки nghttp2, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
ROS-20260819-80-0068
Уязвимость nghttp2
ROS-20260819-73-0068
Уязвимость nghttp2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58055 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-58055 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-58055 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length | 0% Низкий | 3 месяца назад | ||
CVE-2026-58055 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade re ... | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21302-1 Security update for nghttp2 | 0% Низкий | 2 месяца назад | ||
SUSE-SU-2026:4029-1 Security update for nghttp2 | 0% Низкий | 15 дней назад | ||
SUSE-SU-2026:3154-1 Security update for nghttp2 | 0% Низкий | 2 месяца назад | ||
SUSE-SU-2026:3153-1 Security update for nghttp2 | 0% Низкий | 2 месяца назад | ||
RLSA-2026:55804 Moderate: nghttp2 security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:54662 Moderate: nghttp2 security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:54650 Moderate: nghttp2 security update | 0% Низкий | около 1 месяца назад | ||
GHSA-xrr7-82jr-v58x nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
ELSA-2026-55804 ELSA-2026-55804: nghttp2 security update (MODERATE) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-54662 ELSA-2026-54662: nghttp2 security update (MODERATE) | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-54650 ELSA-2026-54650: nghttp2 security update (MODERATE) | 0% Низкий | около 1 месяца назад | ||
BDU:2026-08977 Уязвимость компонента nghttpx библиотеки nghttp2, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
ROS-20260819-80-0068 Уязвимость nghttp2 | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
ROS-20260819-73-0068 Уязвимость nghttp2 | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу