PT-2026-55438 · Linux Mint+1 · Libnghttp2-14+6

Published

2026-07-02

·

Updated

2026-07-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions nghttp2 (affected versions not specified)
Description The nghttp2 nghttpx proxy incorrectly handles HTTP/1.1 Upgrade requests that contain a Content-Length header and a body. This flaw allows a remote attacker to conduct HTTP request and response smuggling attacks against backend services. Request smuggling occurs when the proxy and the backend server disagree on where a request ends, allowing an attacker to "smuggle" a hidden request within another.
Recommendations Update the following packages to version 1.59.0-1ubuntu0.4: libnghttp2-14 libnghttp2-dev libnghttp2-doc nghttp2 nghttp2-client nghttp2-proxy nghttp2-server
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

USN-8495-1

Affected Products

Libnghttp2-14
Libnghttp2-Dev
Libnghttp2-Doc
Nghttp2
Nghttp2-Client
Nghttp2-Proxy
Nghttp2-Server