[CLSA-2026:1787754280] nghttp2: Fix of CVE-2026-58055
Type:
security
Severity:
Moderate
Release date:
2026-08-26 14:24:59 UTC
Description:
- CVE-2026-58055: fix HTTP request/response smuggling via HTTP/1.1 Upgrade request with Content-Length
CVEs fixed:
Updated packages:
  • libnghttp2-1.43.0-5.el9_2.1.tuxcare.els3.i686.rpm
    sha:5f83061327dfddd4d43fc4668ab40ac2c0e94b61c400923af8a2c0d931ed0243
  • libnghttp2-1.43.0-5.el9_2.1.tuxcare.els3.x86_64.rpm
    sha:563098279f112419e23e5edea8efe4fc1560718c2ef70aaa9bb88ca94cbdeae1
  • libnghttp2-devel-1.43.0-5.el9_2.1.tuxcare.els3.i686.rpm
    sha:1ce56cf4c7b4f542e54112ebec90196f156f198c70e83b1ecd7b1874e39717af
  • libnghttp2-devel-1.43.0-5.el9_2.1.tuxcare.els3.x86_64.rpm
    sha:978497f407e9eee738ebadca5c9ec607f519574e1fabf39847ef2fe32a4fb7ef
  • nghttp2-1.43.0-5.el9_2.1.tuxcare.els3.x86_64.rpm
    sha:c1432bda93f18db767d000b1210fb947c1ffdf3cbac58ff02834bf5faa0dd1e1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.