{
  "threat_severity" : "Moderate",
  "public_date" : "2026-06-28T01:32:57Z",
  "bugzilla" : {
    "description" : "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
    "id" : "2493954",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-444",
  "details" : [ "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.", "A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning. This occurs because the proxy ambiguously forwards HTTP/1.1 Upgrade requests that contain a Content-Length header to reusable keep-alive backend connections." ],
  "statement" : "A flaw in nghttp2's nghttpx proxy allows remote HTTP request smuggling and cross-client response poisoning by forwarding malformed HTTP/1.1 Upgrade requests containing a Content-Length body. This is rated Moderate because successful exploitation requires high attack complexity on the backend server.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54650",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "nghttp2-0:1.68.0-3.el10_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55804",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "nghttp2-0:1.33.0-6.el8_10.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54662",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "nghttp2-0:1.43.0-6.el9_8.2"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63135",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/cert-manager-operator-rhel9:1788348522"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63138",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63138",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/jetstack-cert-manager-rhel9:1788348571"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63140",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/cert-manager-istio-csr-rhel9:1788348594"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61783",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1788205779"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61783",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-ui-rhel9:1788206196"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-03T00:00:00Z",
    "advisory" : "RHSA-2026:35454",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "nghttp2-main-1.69.0-3.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-17T00:00:00Z",
    "advisory" : "RHSA-2026:41240",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "curl-main-8.21.0-0.1.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-10T00:00:00Z",
    "advisory" : "RHSA-2026:52414",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "nghttp2-main-1.69.0-5.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-tp-rhel9:1787241211"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-tp-rhel9:1787135742"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs22",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs24",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs:22/nodejs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs:24/nodejs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs:22/nodejs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "nodejs:24/nodejs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-58055\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58055\nhttps://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc\nhttps://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e\nhttps://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length" ],
  "name" : "CVE-2026-58055",
  "mitigation" : {
    "value" : "Configure your WAF or load balancer to drop incoming HTTP/1.1 requests that contain both Upgrade and Content-Length headers. This blocks the malformed traffic at the edge before it can reach the vulnerable proxy without impacting legitimate users.",
    "lang" : "en:us"
  },
  "csaw" : false
}