Sploit.io - Search

Product: h2, version: < 4.3.0

CVE-2025-57804

Severity: Unknown

Description: h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.

CVSS Score: N/A

Affected Products:

  • python-hyper h2 - Versions: < 4.3.0

References: