[Git][security-tracker-team/security-tracker][master] nghttp2 fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 08:10:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
73ef89c2 by Moritz Muehlenhoff at 2026-08-31T09:10:10+02:00
nghttp2 fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -64930,12 +64930,12 @@ CVE-2026-58057 (Flowise before 3.1.3 validates Custom MCP stdio environment vari
 CVE-2026-58056 (RustDesk gates incoming control messages on per-capability flags rathe ...)
 	NOT-FOR-US: RustDesk
 CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade re ...)
-	- nghttp2 <unfixed> (bug #1140917)
+	- nghttp2 1.70.0-1 (bug #1140917)
 	[trixie] - nghttp2 <no-dsa> (Minor issue)
 	[bookworm] - nghttp2 <postponed> (Minor issue)
 	[bullseye] - nghttp2 <postponed> (Minor issue)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc
-	NOTE: https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e
+	NOTE: https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e (v1.70.0)
 CVE-2026-58054
 	REJECTED
 CVE-2026-58053 (Gitea act_runner with the Docker backend (through act 0.262.0) passes  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73ef89c2acd8ea89b903bd4b91dbd39c7f8577fb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73ef89c2acd8ea89b903bd4b91dbd39c7f8577fb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/0ac0b037/attachment.htm>


More information about the debian-security-tracker-commits mailing list