CVE-2026-58055

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-28 02:16

Updated : 2026-06-30 17:41


NVD link : CVE-2026-58055

Mitre link : CVE-2026-58055

CVE.ORG link : CVE-2026-58055


JSON object : View

Products Affected

nghttp2

  • nghttp2
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')