Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:8546 - Security Advisory
Issued:
2026-04-16
Updated:
2026-04-16

RHSA-2026:8546 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: nghttp2 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for nghttp2 is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.

Security Fix(es):

  • nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2448754 - CVE-2026-27135 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

CVEs

  • CVE-2026-27135

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
nghttp2-1.43.0-5.el9_0.4.src.rpm SHA-256: 7776fa2aa4893b8fa69eaac4ed85d389b12d23522d255cd2543db6fe5e6f71f5
ppc64le
libnghttp2-1.43.0-5.el9_0.4.ppc64le.rpm SHA-256: 7017f87ac6891e9caeb12c1ed7af66c97fda70a2aadefd24e0778bbc108ac17a
libnghttp2-debuginfo-1.43.0-5.el9_0.4.ppc64le.rpm SHA-256: 1612ffe769f3112ba8b27659a9bc2c3c2240835e75a2f67ce6a2e86dfa9a8418
nghttp2-debuginfo-1.43.0-5.el9_0.4.ppc64le.rpm SHA-256: c1f51966e9d049a1d13788bf868b1ca1f66c86f35d708a1bc379e24c6d38d76a
nghttp2-debugsource-1.43.0-5.el9_0.4.ppc64le.rpm SHA-256: c0d2a3dd557f52bd85e129c2a7808095051583cdb20462793679e152b277781b

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
nghttp2-1.43.0-5.el9_0.4.src.rpm SHA-256: 7776fa2aa4893b8fa69eaac4ed85d389b12d23522d255cd2543db6fe5e6f71f5
x86_64
libnghttp2-1.43.0-5.el9_0.4.i686.rpm SHA-256: afd633413503e7d03417afaf871580b99c57fbd11201b65d1565d0b836a9c4fc
libnghttp2-1.43.0-5.el9_0.4.x86_64.rpm SHA-256: 2056fb1f57149838aff7691fab39972a9ac8aeb094e4badb2025f45b64105b3e
libnghttp2-debuginfo-1.43.0-5.el9_0.4.i686.rpm SHA-256: 9394817eea728dc0c1a12feb231ac7b79e9784a36cea6d68d021b7ec8e3b131b
libnghttp2-debuginfo-1.43.0-5.el9_0.4.x86_64.rpm SHA-256: 915433cf2a4741bdc93d3a4c406181f43897c9dd129fe6fa22b4411521d5e888
nghttp2-debuginfo-1.43.0-5.el9_0.4.i686.rpm SHA-256: f573ff978e935ddaf86a4b9720d832a52aeb38b48d0e6cbe786f30ec70c74f3e
nghttp2-debuginfo-1.43.0-5.el9_0.4.x86_64.rpm SHA-256: 62355be4c13dc235cbfce37e216bec86b69fa9d41943b418730085aa5c724c30
nghttp2-debugsource-1.43.0-5.el9_0.4.i686.rpm SHA-256: 47da05dde45d57a1455077fc841c9f56262b3798e02547b92ad305acb4e75d3c
nghttp2-debugsource-1.43.0-5.el9_0.4.x86_64.rpm SHA-256: 4ee1ec400f75c4efdd4c367ba15e38498dd7a76447f9ffc57f46080dfd0da29a

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
nghttp2-1.43.0-5.el9_0.4.src.rpm SHA-256: 7776fa2aa4893b8fa69eaac4ed85d389b12d23522d255cd2543db6fe5e6f71f5
aarch64
libnghttp2-1.43.0-5.el9_0.4.aarch64.rpm SHA-256: 367ad65a4687fae8c2b20ca639e72e8f479b36612df88ad46d8d264707e52821
libnghttp2-debuginfo-1.43.0-5.el9_0.4.aarch64.rpm SHA-256: d603c48b8d2b545e4c95986f35048c63b7077313663a7f09e45a2d425dc87e1c
nghttp2-debuginfo-1.43.0-5.el9_0.4.aarch64.rpm SHA-256: 51bc9043ffd69713e8f4f22e9fee2582187e3cf876a7bfe56c26074da59da24e
nghttp2-debugsource-1.43.0-5.el9_0.4.aarch64.rpm SHA-256: b666eda3ffeca1035ac59fda576fc2718327bbfcb913bb54a0b87ce2e7fb3e44

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
nghttp2-1.43.0-5.el9_0.4.src.rpm SHA-256: 7776fa2aa4893b8fa69eaac4ed85d389b12d23522d255cd2543db6fe5e6f71f5
s390x
libnghttp2-1.43.0-5.el9_0.4.s390x.rpm SHA-256: 06aa50b034cc8be10397e774745feda1d8296cafd1dc56b9fc45346e1b09cad9
libnghttp2-debuginfo-1.43.0-5.el9_0.4.s390x.rpm SHA-256: 7a7450796a71033ed22baadea7726e47a2e74e6af9260949f2c412bc0f12ae31
nghttp2-debuginfo-1.43.0-5.el9_0.4.s390x.rpm SHA-256: 93f4cf4fe2aa63c4be6a1aba17780509838a2f445b658ed65d14c53b82e02c0d
nghttp2-debugsource-1.43.0-5.el9_0.4.s390x.rpm SHA-256: 0bc9fae50c77a845f35fa7e3a3604f5b496a1f071bb32eed86703506a3aac2ad

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility