HTTP request smuggling In nghttp2
Description
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 13 | - | ||
debian 14 | - | ||
debian 12 | - | ||
rpm rhel10 | 0:1.68.0-3.el10_2.2 | ||
rpm rhel9 | 0:1.43.0-6.el9_8.2 | ||
rpm rhel8 | 0:1.33.0-6.el8_10.3 | ||
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel10 | - | - |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5.