PT-2025-34706 · H2+2 · H2+2
Sebastianosrt
·
Published
2025-08-23
·
Updated
2026-06-03
·
CVE-2025-57804
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
h2 versions prior to 4.3.0
Description:
h2 is a pure-Python implementation of a HTTP/2 protocol stack. A request splitting issue allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls.
Recommendations:
Update to version 4.3.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Suse
H2