Critical HTTP Request Smuggling Vulnerability in Fedora 43 and 44

Critical HTTP Request Smuggling Vulnerability in Fedora 43 and 44

First seen 11 Aug 2026, 03:47 UTC Linuxsecurity 99% similarity 72.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-58055) affecting the nghttp2 package in Fedora 43 and 44 was disclosed, allowing HTTP request/response smuggling and response-queue poisoning via ambiguous HTTP/1.1 Upgrade requests. This vulnerability impacts systems running the HTTP/2 client, server, and proxy programs. The flaw was published on June 28, 2026, and updates to mitigate the risk were released on August 7, 2026. Users are advised to upgrade to the latest versions (1.66.0-3 for Fedora 43 and 1.68.0-5 for Fedora 44) to secure their systems. The vulnerability poses a significant risk of compromise and escalation of privileges if left unaddressed. The updates can be installed using the dnf package manager. Security professionals are urged to audit Linux privileges to limit potential damage.

Key Points: • CVE-2026-58055 allows HTTP request/response smuggling in nghttp2 package. • Affected systems include Fedora 43 and 44 running the HTTP/2 client and server. • Users must upgrade to patched versions released on August 7, 2026, to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-06-28
CVE-2026-58055 published
A critical vulnerability in nghttp2 was disclosed, allowing HTTP request/response smuggling.
Linuxsecurity
2026-08-07
Patch released for Fedora 43 and 44
Updates were released to fix CVE-2026-58055, addressing the HTTP smuggling vulnerability.
Linuxsecurity
2026-08-11
Critical vulnerability reported in Fedora advisories
Linuxsecurity published advisories highlighting the critical nature of CVE-2026-58055 and the need for immediate updates.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story