CVE-2026-71554

MEDIUM CVSS 3.1: 5.3 EPSS 0.33%
Updated Aug 08, 2026
Python-Hyper
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 4.4.1
Type CWE-444
Vendor Python-Hyper
Public PoC No

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive.

This issue is fixed in version 4.4.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

python-hyper:h2