Количество 4
Количество 4
CVE-2026-71554
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.
CVE-2026-71554
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.
CVE-2026-71554
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...
GHSA-6hr6-w5qg-qmwg
h2: Duplicate Host header could facilitate request smuggling
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-71554 h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1. | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
CVE-2026-71554 h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1. | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
CVE-2026-71554 h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ... | CVSS3: 5.3 | 0% Низкий | 25 дней назад | |
GHSA-6hr6-w5qg-qmwg h2: Duplicate Host header could facilitate request smuggling | CVSS3: 5.3 | 0% Низкий | 25 дней назад |
Уязвимостей на страницу