Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-71554

Опубликовано: 06 авг. 2026
Источник: debian
EPSS Низкий

Описание

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-h2unfixedpackage
python-h2no-dsatrixiepackage

Примечания

  • https://github.com/python-hyper/h2/security/advisories/GHSA-6hr6-w5qg-qmwg

  • Fixed by: https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6 (4.4.1)

EPSS

Процентиль: 37%
0.00443
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
nvd
25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
github
25 дней назад

h2: Duplicate Host header could facilitate request smuggling

EPSS

Процентиль: 37%
0.00443
Низкий