Skip to content
Fedora 44 nghttp2 Important HTTP Smuggling CVE-2026

Fedora 44 nghttp2 Important HTTP Smuggling CVE-2026

Linuxsecurity LinuxSecurity Advisories August 9, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

This package contains the HTTP/2 client, server and proxy programs.

fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

* Fri Aug 7 2026 Jan Macku - 1.68.0-5 - fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

* Fri Aug 7 2026 Jan Macku - 1.68.0-5 - fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

[ 1 ] Bug #2502788 - CVE-2026-58055 nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-084c991d17' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Platforms (1)