RHSA-2026:55804: Moderate: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3 - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-6.el8_10.3.aa - Compensating control
Apply the Red Hat security update for the nghttp2 moderate security advisory referenced for the HTTP Request/Response Smuggling and Response-Queue Poisoning issue (CVE-2026-58055), as described in the linked advisory article (https://access.redhat.com/articles/11258).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55804?
The severity of RHSA-2026:55804 is classified as moderate.
What vulnerabilities are addressed by RHSA-2026:55804?
RHSA-2026:55804 addresses HTTP Request/Response Smuggling and Response-Queue Poisoning vulnerabilities identified by CVE-2026-58055.
How do I fix RHSA-2026:55804?
To fix RHSA-2026:55804, you should update to the latest version of the affected packages, including redhat/nghttp2 and redhat/libnghttp2.
What software is affected by RHSA-2026:55804?
The affected software includes redhat/nghttp2, redhat/libnghttp2, and their associated debuginfo and development packages.
When was RHSA-2026:55804 published?
RHSA-2026:55804 was published on August 17, 2026.