Skip to content

CVE-2026-58055

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 9, 2026
Last Seen
August 11, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability (CVE-2026-58055) affecting the nghttp2 package in Fedora 43 and 44 was disclosed, allowing HTTP request/response smuggling and response-queue poisoning via ambiguous HTTP/1.1 Upgrade requests. This vulnerability impacts systems running the HTTP/2 client, server, and proxy pr...

Public Exploits

Checking GitHub for proof-of-concept code…