UBUNTU-CVE-2026-58055

Source
https://ubuntu.com/security/CVE-2026-58055
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-58055
Upstream
Downstream
Related
Published
2026-06-28T02:16:00Z
Modified
2026-07-02T18:04:25.552132645Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

References

Affected packages

Ubuntu:22.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.43.0-1ubuntu0.4

Affected versions

1.*
1.43.0-1
1.43.0-1build1
1.43.0-1build2
1.43.0-1build3
1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.2
1.43.0-1ubuntu0.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.43.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.43.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.43.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.43.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.43.0-1ubuntu0.4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:24.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.59.0-1ubuntu0.4

Affected versions

1.*
1.55.1-1
1.57.0-1
1.58.0-1
1.59.0-1
1.59.0-1build1
1.59.0-1build2
1.59.0-1build4
1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.2
1.59.0-1ubuntu0.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.59.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.59.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.59.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.59.0-1ubuntu0.4"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.59.0-1ubuntu0.4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:25.10
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.64.0-1.1ubuntu1.2

Affected versions

1.*
1.64.0-1ubuntu1
1.64.0-1.1
1.64.0-1.1build1
1.64.0-1.1ubuntu1
1.64.0-1.1ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.64.0-1.1ubuntu1.2"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.64.0-1.1ubuntu1.2"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.64.0-1.1ubuntu1.2"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.64.0-1.1ubuntu1.2"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.64.0-1.1ubuntu1.2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:26.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.68.0-2ubuntu0.2

Affected versions

1.*
1.64.0-1.1ubuntu1
1.64.0-1.1ubuntu2
1.68.0-1
1.68.0-2
1.68.0-2ubuntu0.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.68.0-2ubuntu0.2"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.68.0-2ubuntu0.2"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.68.0-2ubuntu0.2"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.68.0-2ubuntu0.2"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.68.0-2ubuntu0.2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:Pro:16.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.7-1
1.*
1.3.4-2
1.4.0-1
1.4.0-2
1.5.0-2
1.6.0-1
1.7.0-1
1.7.1-1
1.7.1-1ubuntu0.1~esm1
1.7.1-1ubuntu0.1~esm2
1.7.1-1ubuntu0.1~esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.7.1-1ubuntu0.1~esm3"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.7.1-1ubuntu0.1~esm3"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.7.1-1ubuntu0.1~esm3"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.7.1-1ubuntu0.1~esm3"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.7.1-1ubuntu0.1~esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:Pro:18.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.25.0-1
1.27.0-1
1.28.0-1
1.29.0-1
1.29.0-1build1
1.30.0-1
1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm1
1.30.0-1ubuntu1+esm2
1.30.0-1ubuntu1+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.30.0-1ubuntu1+esm3"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.30.0-1ubuntu1+esm3"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.30.0-1ubuntu1+esm3"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.30.0-1ubuntu1+esm3"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.30.0-1ubuntu1+esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"
Ubuntu:Pro:20.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.39.2-1
1.40.0-1
1.40.0-1build1
1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3
1.40.0-1ubuntu0.3+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnghttp2-14",
            "binary_version": "1.40.0-1ubuntu0.3+esm1"
        },
        {
            "binary_name": "nghttp2",
            "binary_version": "1.40.0-1ubuntu0.3+esm1"
        },
        {
            "binary_name": "nghttp2-client",
            "binary_version": "1.40.0-1ubuntu0.3+esm1"
        },
        {
            "binary_name": "nghttp2-proxy",
            "binary_version": "1.40.0-1ubuntu0.3+esm1"
        },
        {
            "binary_name": "nghttp2-server",
            "binary_version": "1.40.0-1ubuntu0.3+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58055.json"