PT-2025-17850 · H11+6 · H11+6

Jeppw

·

Published

2025-04-24

·

Updated

2026-06-03

·

CVE-2025-43859

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions h11 versions prior to 0.16.0
Description h11 is a Python implementation of HTTP/1.1. A leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.
Recommendations Update to h11 version 0.16.0 to fix the parsing vulnerability. As a temporary workaround, consider disabling the vulnerable component until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the vulnerable function in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06251
CVE-2025-43859
GHSA-VQFR-H8MV-GHFJ
OESA-2025-1496
OESA-2025-1497
OPENSUSE-SU-2025:15032-1
OPENSUSE-SU-2025_1430-1
RHSA-2025:7535
RHSA-2025:7536
SUSE-SU-2025:1430-1
SUSE-SU-2025:20330-1
SUSE-SU-2025:20331-1
SUSE-SU-2025_1430-1
USN-7503-1

Affected Products

Astra Linux
Debian
Linuxmint
Red Os
Suse
Ubuntu
H11