RHSA-2026:54662: Moderate: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2 - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.43.0-6.el9_8.2.aa - Upgrade
Upgrade
libnghttp2 (nghttp2)to a version that resolves this vulnerability.Patch CVE-2026-58055
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54662?
The severity of RHSA-2026:54662 is medium with a score of 4.
What does RHSA-2026:54662 address?
RHSA-2026:54662 addresses a security update for nghttp2 to mitigate vulnerabilities.
How do I fix RHSA-2026:54662?
To fix RHSA-2026:54662, users should apply the latest available updates as provided in the errata.
Which software is affected by RHSA-2026:54662?
RHSA-2026:54662 affects various Red Hat Enterprise Linux versions across multiple architectures including Power and ARM.
When was RHSA-2026:54662 published?
RHSA-2026:54662 was published on August 13, 2026.