OPENSUSE-SU-2026:21302-1
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 10 Jul 2026, 13:13
Last modified:13 Jul 2026, 18:24
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Jul 2026, 13:13
Published
Vulnerability first disclosed
13 Jul 2026, 18:24
Last Modified
Vulnerability information updated
Description
Security update for nghttp2 This update for nghttp2 fixes the following issue - CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489).
Affected Systems
- opensuse•nghttp2&distro=openSUSE Leap 16.0
< 1.64.0-160000.4.1