[CLSA-2026:1787308423] nghttp2: Fix of CVE-2026-58055
Type:
security
Severity:
Moderate
Release date:
2026-08-21 10:33:53 UTC
Description:
- CVE-2026-58055: reject Upgrade/CONNECT requests carrying a body and stop forwarding them onto reusable keep-alive backend connections
CVEs fixed:
Updated packages:
  • libnghttp2-1.43.0-6.el9_6.tuxcare.els3.i686.rpm
    sha:fe2f55506820f488159caf24b5d8561390e10a19baf8146eaf7ac2707d490e6b
  • libnghttp2-1.43.0-6.el9_6.tuxcare.els3.x86_64.rpm
    sha:10aef24437e64ab1d93306ccde45323ea231c58f8412d9b9e9ea90351e4efba6
  • libnghttp2-devel-1.43.0-6.el9_6.tuxcare.els3.i686.rpm
    sha:93f6f9262906f4d3bca32c20ae713aab3eed8737ff3ad860f384f73138f2bad7
  • libnghttp2-devel-1.43.0-6.el9_6.tuxcare.els3.x86_64.rpm
    sha:4ef048792e101aa127ec566fb203dd46dd61d98ac71c56a94cdd0cfbae3b487d
  • nghttp2-1.43.0-6.el9_6.tuxcare.els3.x86_64.rpm
    sha:dff7ca843e9715f1af3ce4a6a5fbcfad20ced5f7a3acda52c2934cd4861c7203
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.