RHSA-2026:54650: Moderate: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.68.0-3.el10_2.2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54650?
The severity of RHSA-2026:54650 is classified as medium with a score of 4.
How do I fix RHSA-2026:54650?
To fix RHSA-2026:54650, you should update nghttp2 to the latest available version provided by Red Hat.
What software is affected by RHSA-2026:54650?
RHSA-2026:54650 affects various versions of Red Hat Enterprise Linux, including x86_64, ARM 64, and IBM z Systems.
When was RHSA-2026:54650 published?
RHSA-2026:54650 was published on August 13, 2026.
What type of update does RHSA-2026:54650 provide?
RHSA-2026:54650 provides a security update for the nghttp2 software.