Linuxsecurity
Critical HTTP Request Smuggling Vulnerability in Fedora 43 and 44
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability (CVE-2026-58055) affecting the nghttp2 package in Fedora 43 and 44 was disclosed, allowing HTTP request/response smuggling and response-queue poisoning via ambiguous HTTP/1.1 Upgrade requests. This vulnerability impacts systems running the HTTP/2 client, server, and proxy programs. The flaw was published on June 28, 2026, and updates to mitigate the risk were released on August 7, 2026. Users are advised to upgrade to the latest versions (1.66.0-3 for Fedora 43 and 1.68.0-5 for Fedora 44) to secure their systems. The vulnerability poses a significant risk of compromise and escalation of privileges if left unaddressed. The updates can be installed using the dnf package manager. Security professionals are urged to audit Linux privileges to limit potential damage.
Key Points: • CVE-2026-58055 allows HTTP request/response smuggling in nghttp2 package. • Affected systems include Fedora 43 and 44 running the HTTP/2 client and server. • Users must upgrade to patched versions released on August 7, 2026, to mitigate risks.