{"id":"AZL-91451","summary":"CVE-2026-58055 affecting package fluent-bit for versions less than 3.1.10-6","details":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.","modified":"2026-08-30T05:26:50Z","published":"2026-06-28T02:16:32Z","upstream":["CVE-2026-58055"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055"}],"affected":[{"package":{"name":"fluent-bit","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/fluent-bit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.10-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91451.json"}}],"schema_version":"1.9.0"}