By vendor

Nghttp2 vulnerabilities

Known CVEs affecting Nghttp2 products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-58055MEDIUM 5.4

    nghttp2's nghttpx proxy (through version 1.69.0) has a flaw in how it handles HTTP upgrade requests when they include both a Content-Length header and a message body. When forwarding these requests to backend servers over persistent connections, the proxy re-adds upgrade-related headers while passing the Content-Length unchanged. If a backend server interprets this ambiguous message differently than the proxy intended, an attacker can inject malicious HTTP requests or poison response queues, causing one client to receive another client's response.