PT-2026-55438 · Linux Mint+1 · Libnghttp2-14+6
Published
2026-07-02
·
Updated
2026-07-02
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
nghttp2 (affected versions not specified)
Description
The nghttp2 nghttpx proxy incorrectly handles HTTP/1.1 Upgrade requests that contain a
Content-Length header and a body. This flaw allows a remote attacker to conduct HTTP request and response smuggling attacks against backend services. Request smuggling occurs when the proxy and the backend server disagree on where a request ends, allowing an attacker to "smuggle" a hidden request within another.Recommendations
Update the following packages to version 1.59.0-1ubuntu0.4:
libnghttp2-14
libnghttp2-dev
libnghttp2-doc
nghttp2
nghttp2-client
nghttp2-proxy
nghttp2-server
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libnghttp2-14
Libnghttp2-Dev
Libnghttp2-Doc
Nghttp2
Nghttp2-Client
Nghttp2-Proxy
Nghttp2-Server