← Vulnerability feed

Vulnerability record · CVE-2026-58055 · published 28 June 2026

CVE-2026-58055: Nghttp2 http request smuggling vulnerability

Nghttp2 · Nghttp2

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

6.3 CVSS 4.0 Medium EPSS 0.32% · top 77.7% CWE-444 · HTTP request smuggling
6.3CVSS 4.0 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
30 Jun 2026Last modified by NVD

Description

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-58055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2015-8659Apple mac os x memory buffer overflow vulnerabilityThe idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.EPSS 4.0%7.5CVE-2026-27135Nghttp2 vulnerabilitynghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incomi…EPSS 0.89%7.5CVE-2023-35945Envoyproxy envoy uncontrolled resource consumption vulnerabilityEnvoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiv…EPSS 1.3%7.5CVE-2020-11080Nghttp2 uncontrolled resource consumption vulnerabilityIn nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal…EPSS 5.3%7.5CVE-2018-1000168Nghttp2 improper input validation vulnerabilitynghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result …EPSS 11%5.3CVE-2024-28182nghttp2 HTTP/2 CONTINUATION frame flood causes CPU exhaustionnghttp2 before 1.61.0 keeps reading an unbounded number of HTTP/2 CONTINUATION frames after a stream is reset, in order to keep the HPACK context in …EPSS 85%analysed3.3CVE-2016-1544Nghttp2 uncontrolled resource consumption vulnerabilitynghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2026-58055), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.