{"id":"GHSA-63cx-g855-hvv4","summary":"mitmproxy binaries embed a vulnerable python-hyper/h2 dependency","details":"mitmproxy 12.1.1 and below embed python-hyper/h2 ≤ v4.2.0, which has a gap in its HTTP/2 header validation. This enables request smuggling attacks when mitmproxy is in a configuration where it translates HTTP/2 to HTTP/1. For example, this affects reverse proxies to `http://` backends. It does not affect mitmproxy's regular mode.\n\nAll users are encouraged to upgrade to mitmproxy 12.1.2, which includes a fixed version of h2.\n\nMore details about the vulnerability itself can be found at https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h.","modified":"2026-09-10T03:50:26.707538775Z","published":"2025-08-25T21:01:00Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1395","CWE-444"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-08-25T21:01:00Z"},"references":[{"type":"WEB","url":"https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-63cx-g855-hvv4"},{"type":"WEB","url":"https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h"},{"type":"PACKAGE","url":"https://github.com/mitmproxy/mitmproxy"}],"affected":[{"package":{"name":"mitmproxy","ecosystem":"PyPI","purl":"pkg:pypi/mitmproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.1.2"}]}],"versions":["0.10","0.10.1","0.11","0.11.1","0.11.2","0.11.3","0.12.0","0.12.1","0.13","0.14.0","0.15","0.16","0.17","0.18.1","0.18.2","0.18.3","0.8","0.8.1","0.9","0.9.1","0.9.2","1.0.0","1.0.1","1.0.2","10.0.0","10.1.0","10.1.1","10.1.2","10.1.3","10.1.4","10.1.5","10.1.6","10.2.0","10.2.1","10.2.2","10.2.3","10.2.4","10.3.0","10.3.1","10.4.0","10.4.1","10.4.2","11.0.0","11.0.1","11.0.2","11.1.0","11.1.2","11.1.3","12.0.0","12.0.1","12.1.0","12.1.1","2.0.0","2.0.1","2.0.2","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","4.0.0","4.0.1","4.0.3","4.0.4","5.0.0","5.0.1","5.1.0","5.1.1","5.2","5.3.0","6.0.0","6.0.1","6.0.2","7.0.0","7.0.1","7.0.2","7.0.3","7.0.4","8.0.0","8.1.0","8.1.1","9.0.0","9.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-63cx-g855-hvv4/GHSA-63cx-g855-hvv4.json","last_known_affected_version_range":"\u003c= 12.1.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}