shield Security update for nghttp2
SUSE-SLE-Module-Basesystem-15-SP7-2026-4029


This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489).

  • Release Date
    Sep 7 2026
  • References
    Bugzilla: 1269489
    CVEs: CVE-2026-58055
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

Basesystem Module 15.7 ppc64le
  • Packages
    libnghttp2-14
    Shared library for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    libnghttp2-devel
    Development files for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    nghttp2
    Implementation of Hypertext Transfer Protocol version 2 in C
    1.64.0-150700.3.6.1 lock src
Basesystem Module 15.7 s390x
  • Packages
    libnghttp2-14
    Shared library for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    libnghttp2-devel
    Development files for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    nghttp2
    Implementation of Hypertext Transfer Protocol version 2 in C
    1.64.0-150700.3.6.1 lock src
Basesystem Module 15.7 aarch64
  • Packages
    libnghttp2-14
    Shared library for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    libnghttp2-devel
    Development files for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    nghttp2
    Implementation of Hypertext Transfer Protocol version 2 in C
    1.64.0-150700.3.6.1 lock src
Basesystem Module 15.7 x86_64
  • Packages
    libnghttp2-14
    Shared library for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    libnghttp2-14-32bit
    Shared library for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    libnghttp2-devel
    Development files for nghttp2
    1.64.0-150700.3.6.1 lock rpm
    nghttp2
    Implementation of Hypertext Transfer Protocol version 2 in C
    1.64.0-150700.3.6.1 lock src