Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-71554

25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-71554

25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-71554

25 дней назад

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6hr6-w5qg-qmwg

25 дней назад

h2: Duplicate Host header could facilitate request smuggling

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-71554

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-71554

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.

CVSS3: 5.3
0%
Низкий
25 дней назад
debian логотип
CVE-2026-71554

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...

CVSS3: 5.3
0%
Низкий
25 дней назад
github логотип
GHSA-6hr6-w5qg-qmwg

h2: Duplicate Host header could facilitate request smuggling

CVSS3: 5.3
0%
Низкий
25 дней назад

Уязвимостей на страницу