Fedora Account System
Red Hat Associate
Red Hat Customer
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:54650 https://access.redhat.com/errata/RHSA-2026:54650
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54662 https://access.redhat.com/errata/RHSA-2026:54662
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:55804 https://access.redhat.com/errata/RHSA-2026:55804