Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71554

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

EPSS

Процентиль: 25%
0.00325
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.3
ubuntu
25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
debian
25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...

CVSS3: 5.3
github
25 дней назад

h2: Duplicate Host header could facilitate request smuggling

EPSS

Процентиль: 25%
0.00325
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-444