Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:7667 - Security Advisory
Issued:
2026-04-13
Updated:
2026-04-13

RHSA-2026:7667 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: nghttp2 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for nghttp2 is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.

Security Fix(es):

  • nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

Fixes

  • BZ - 2448754 - CVE-2026-27135 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

CVEs

  • CVE-2026-27135

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
x86_64
libnghttp2-1.33.0-6.el8_10.2.i686.rpm SHA-256: 2cce0a16df355b585b4b7e708ba040e20fc5ec3d16855123a823f8f9a6978f57
libnghttp2-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 861f14d20f3a9d637198572ac7c9fcfbafa6847f3bb1ce753c9e8801d80b0d62
libnghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 4ae58ede5ea7e5527defb9b3e6bf0d095acc391b600d1960837c2a42c4452418
libnghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: b1c97bdcef18dd134bdc04560080cde669ab082863174a259b54949ee319ada3
nghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 7b7754cd1409447973b696d5a1a76a234a6fda7f28525a4dee84c805b0490947
nghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 8d5e6d4b962226fa38b7c692b0ef83d4622d25bda0f7edb3e59a33f61a4cb53e
nghttp2-debugsource-1.33.0-6.el8_10.2.i686.rpm SHA-256: 156f32bfd248e1dbe75e110d3cab4f8b418c9abe30295cf67385140b5c4408dc
nghttp2-debugsource-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: a1774c49cce6a8c8c7dbee754e4535ea118774d6916b20fa738ff37e240db911

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
s390x
libnghttp2-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 194322cd4085d9197b073c008b44a4009284d0f4c05cc09a16c92a52486a3f35
libnghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 2723413753d0f59382903233b5284d7b8416bc6383efb0adddacb2773b6fb61f
nghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: f64b49323891d84c01bf2795537b2e88ee88610fb3825bc7dd1132453164d323
nghttp2-debugsource-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 4cdadc4d2b9764592feafeb02047cb158fc70a1f8fa795596f0d0843b6e55610

Red Hat Enterprise Linux for Power, little endian 8

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
ppc64le
libnghttp2-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 6870765b541766dabe49c10aed638de1efa23fd52e80b43004f36e2bf18fc43e
libnghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 7a73d06e263d995acec02e6fed78d88b68e91f0c291e91d3d986c8d9801b8382
nghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 02aa93f9fa16a5a0c4cafc7e2464a7b583b12eea1b5c2397f6b0daca05918c3b
nghttp2-debugsource-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 64514718fd909693371dd6923a0840ded1393f6abbf7c4bdb2f6dd1ea1bc8db4

Red Hat Enterprise Linux for ARM 64 8

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
aarch64
libnghttp2-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 7742ec97305d556cd9accbb2f2cf5a926e2363fa8109782c060d1d5066a8f80e
libnghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 94a57da5f4eac1bc5ebff31395a64613496a753d6f1dc452d343df561b5e6d23
nghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: df9028d8d6fad5b625b0791bc1a16408a3dc834de061aa2c1a0b67b375c70c4e
nghttp2-debugsource-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: e9fd0fd001c021a30cad27701262c378cf1282d370f2fbed8af81de197e86647

Red Hat CodeReady Linux Builder for x86_64 8

SRPM
x86_64
libnghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 4ae58ede5ea7e5527defb9b3e6bf0d095acc391b600d1960837c2a42c4452418
libnghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: b1c97bdcef18dd134bdc04560080cde669ab082863174a259b54949ee319ada3
libnghttp2-devel-1.33.0-6.el8_10.2.i686.rpm SHA-256: b519671f4145966f18f1c150b4fc30bc507705c120f46f2e54a6efd6d439413c
libnghttp2-devel-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 45338c21dd149ac2900e0b8d2f59a1d25ac5eacc2cec6e0216326d3c35c7cd6d
nghttp2-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 1b8a2ea1378732be072a57ea78b432e1df14b16fbc7affb126301873c9cb913e
nghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 7b7754cd1409447973b696d5a1a76a234a6fda7f28525a4dee84c805b0490947
nghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 8d5e6d4b962226fa38b7c692b0ef83d4622d25bda0f7edb3e59a33f61a4cb53e
nghttp2-debugsource-1.33.0-6.el8_10.2.i686.rpm SHA-256: 156f32bfd248e1dbe75e110d3cab4f8b418c9abe30295cf67385140b5c4408dc
nghttp2-debugsource-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: a1774c49cce6a8c8c7dbee754e4535ea118774d6916b20fa738ff37e240db911

Red Hat CodeReady Linux Builder for Power, little endian 8

SRPM
ppc64le
libnghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 7a73d06e263d995acec02e6fed78d88b68e91f0c291e91d3d986c8d9801b8382
libnghttp2-devel-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 8444363aa53ade765ae4e8cdfb471a8e0e88ec29180db8daa641276bcc9602b7
nghttp2-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 637f2fccc8f3f991a3d09adcbb1168e3f001c74eb0d8057ead02eaf65cee16d7
nghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 02aa93f9fa16a5a0c4cafc7e2464a7b583b12eea1b5c2397f6b0daca05918c3b
nghttp2-debugsource-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 64514718fd909693371dd6923a0840ded1393f6abbf7c4bdb2f6dd1ea1bc8db4

Red Hat CodeReady Linux Builder for ARM 64 8

SRPM
aarch64
libnghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 94a57da5f4eac1bc5ebff31395a64613496a753d6f1dc452d343df561b5e6d23
libnghttp2-devel-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 48f5ee25e5f1c70a6e6056e78252e75e23bfd9d7259afc06a6141ff516bbbcba
nghttp2-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 3fb48703190e522dce8d18517410ffa4ef673ab6ae14cf9ce6b9250592a48c6c
nghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: df9028d8d6fad5b625b0791bc1a16408a3dc834de061aa2c1a0b67b375c70c4e
nghttp2-debugsource-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: e9fd0fd001c021a30cad27701262c378cf1282d370f2fbed8af81de197e86647

Red Hat CodeReady Linux Builder for IBM z Systems 8

SRPM
s390x
libnghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 2723413753d0f59382903233b5284d7b8416bc6383efb0adddacb2773b6fb61f
libnghttp2-devel-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 060af286e5811847ae74dcd2135df23816cdfb39e06b701e49bb8d2892f10898
nghttp2-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 69883800af726d7bca986c8407c22a6f6e0b763dbd244ef8caed9f62d6cccc6a
nghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: f64b49323891d84c01bf2795537b2e88ee88610fb3825bc7dd1132453164d323
nghttp2-debugsource-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 4cdadc4d2b9764592feafeb02047cb158fc70a1f8fa795596f0d0843b6e55610

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
x86_64
libnghttp2-1.33.0-6.el8_10.2.i686.rpm SHA-256: 2cce0a16df355b585b4b7e708ba040e20fc5ec3d16855123a823f8f9a6978f57
libnghttp2-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 861f14d20f3a9d637198572ac7c9fcfbafa6847f3bb1ce753c9e8801d80b0d62
libnghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 4ae58ede5ea7e5527defb9b3e6bf0d095acc391b600d1960837c2a42c4452418
libnghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: b1c97bdcef18dd134bdc04560080cde669ab082863174a259b54949ee319ada3
nghttp2-debuginfo-1.33.0-6.el8_10.2.i686.rpm SHA-256: 7b7754cd1409447973b696d5a1a76a234a6fda7f28525a4dee84c805b0490947
nghttp2-debuginfo-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: 8d5e6d4b962226fa38b7c692b0ef83d4622d25bda0f7edb3e59a33f61a4cb53e
nghttp2-debugsource-1.33.0-6.el8_10.2.i686.rpm SHA-256: 156f32bfd248e1dbe75e110d3cab4f8b418c9abe30295cf67385140b5c4408dc
nghttp2-debugsource-1.33.0-6.el8_10.2.x86_64.rpm SHA-256: a1774c49cce6a8c8c7dbee754e4535ea118774d6916b20fa738ff37e240db911

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
aarch64
libnghttp2-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 7742ec97305d556cd9accbb2f2cf5a926e2363fa8109782c060d1d5066a8f80e
libnghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: 94a57da5f4eac1bc5ebff31395a64613496a753d6f1dc452d343df561b5e6d23
nghttp2-debuginfo-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: df9028d8d6fad5b625b0791bc1a16408a3dc834de061aa2c1a0b67b375c70c4e
nghttp2-debugsource-1.33.0-6.el8_10.2.aarch64.rpm SHA-256: e9fd0fd001c021a30cad27701262c378cf1282d370f2fbed8af81de197e86647

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
ppc64le
libnghttp2-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 6870765b541766dabe49c10aed638de1efa23fd52e80b43004f36e2bf18fc43e
libnghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 7a73d06e263d995acec02e6fed78d88b68e91f0c291e91d3d986c8d9801b8382
nghttp2-debuginfo-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 02aa93f9fa16a5a0c4cafc7e2464a7b583b12eea1b5c2397f6b0daca05918c3b
nghttp2-debugsource-1.33.0-6.el8_10.2.ppc64le.rpm SHA-256: 64514718fd909693371dd6923a0840ded1393f6abbf7c4bdb2f6dd1ea1bc8db4

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
nghttp2-1.33.0-6.el8_10.2.src.rpm SHA-256: e772c6e8cf40297ecdbd0a022507eb5e7b116f9569ab0f2a4bb470b4cfa2eb00
s390x
libnghttp2-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 194322cd4085d9197b073c008b44a4009284d0f4c05cc09a16c92a52486a3f35
libnghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 2723413753d0f59382903233b5284d7b8416bc6383efb0adddacb2773b6fb61f
nghttp2-debuginfo-1.33.0-6.el8_10.2.s390x.rpm SHA-256: f64b49323891d84c01bf2795537b2e88ee88610fb3825bc7dd1132453164d323
nghttp2-debugsource-1.33.0-6.el8_10.2.s390x.rpm SHA-256: 4cdadc4d2b9764592feafeb02047cb158fc70a1f8fa795596f0d0843b6e55610

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility