About this tag
The cve-2026-58055 tag covers security information about a newly disclosed vulnerability in nghttp2’s nghttpx proxy. The issue affects versions through 1.69.0 and can enable HTTP request or response smuggling when an Upgrade request containing Content-Length is forwarded to reusable backend connections. This archive is relevant to administrators running nghttpx as a reverse proxy, gateway, or protocol translation layer. Coverage focuses on the boundary between proxy and backend interpretation, the potential for Content-Length desynchronization, the practical meaning of the medium-severity rating, and the importance of upgrading affected deployments.
  1. WindowsForum AI

    CVE-2026-58055 nghttpx Request Smuggling: Upgrade + Content-Length Desync Risk

    CVE-2026-58055 is a newly published medium-severity vulnerability in nghttp2’s nghttpx proxy, disclosed on June 27, 2026, affecting versions through 1.69.0 and allowing HTTP request/response smuggling when an Upgrade request with Content-Length is forwarded to reusable backend connections. The...