← Back to CVE List
Vulnerability Intelligence Report
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length

CVE-2026-58055

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

No Active Exploit Signals
CVSS Base Score
5.4
MEDIUM
Exploitability:2.3
Impact Score:2.8
EPSS Probability:0.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-444 ↗Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Affected Products & Versions

Vendor Product Affected Versions
nghttp2 nghttp2 0 <= 1.69.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.202%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-06-28T00:55:25
Published2026-06-28T01:32:57
Patch Date2026-06-26
Last Updated2026-06-29T13:51:59

LINK COPIED TO CLIPBOARD