VDB
RHSA-2026%3A8538
RHSA-2026%3A8538
PUBLISHED
CVSS 7.5 HIGH
An update for nghttp2 is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.6 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nghttp2 | ||
| Red Hat Enterprise Linux BaseOS E4S (v.8.6) | ||
| Red Hat Enterprise Linux BaseOS AUS (v.8.6) | ||
| libnghttp2 | ||
| Red Hat Enterprise Linux BaseOS TUS (v.8.6) |
Timeline
- Apr 16, 2026 CVE Published
- Apr 23, 2026 CVE Updated
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- May 15, 2026 Security Advisory