Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.3

CVE-2026-58055: nghttpx Proxy Vulnerable to HTTP Request Smuggling

CVE-2026-58055
Summary

nghttpx proxy versions up to 1.69.0 may allow attackers to manipulate HTTP requests and responses, potentially leading to security breaches. This vulnerability affects how the proxy handles certain types of HTTP requests, which could be exploited by malicious actors. To protect your network, update nghttpx to a version newer than 1.69.0.

Original title
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade an...
Original description
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
nvd CVSS3.1 5.4
nvd CVSS4.0 6.3
Vulnerability type
CWE-444
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026