CVE-2026-58055Active Exploitation(nghttp2 / nghttp2)

LOWCVSS 6.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for nghttp2 nghttp2 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nghttp2

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
nghttp2

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-28: 2Active Exploitation · 2026-06-28: 1Technical Details · 2026-06-28: 106-28
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting nghttp2 (CVE-2026-58055) https://vuldb.com/vuln/374509/cti

    Post summary

    The post indicates that malicious actors are actively exploiting CVE-2026-58055 in nghttp2, with no additional MitM or patch details provided.

    00010117
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58055 HTTP Request Smuggling in nghttp2 nghttpx Proxy Through Version 1.69.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58055

    Post summary

    The post announces CVE-2026-58055 as an HTTP Request Smuggling vulnerability affecting nghttp2 nghttpx Proxy up to version 1.69.0, but does not provide PoC, exploit, or patch information.

    00010123
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnghttp2nghttp2---

Explore more