{"id":"PYSEC-2026-1435","summary":"h2 allows HTTP Request Smuggling due to illegal characters in headers","details":"### Summary\n\nHTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls.","aliases":["CVE-2025-57804","GHSA-847f-9342-265h"],"modified":"2026-07-07T17:47:39.182570446Z","published":"2026-07-07T16:03:01.951354Z","references":[{"type":"WEB","url":"https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57804"},{"type":"WEB","url":"https://github.com/python-hyper/h2/commit/035e9899f95e3709af098f578bfc3cd302298e3a"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00004.html"},{"type":"PACKAGE","url":"https://pypi.org/project/h2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-847f-9342-265h"}],"affected":[{"package":{"name":"h2","ecosystem":"PyPI","purl":"pkg:pypi/h2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0"}]}],"versions":["0.1.0","1.0.0","1.1.0","1.1.1","2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.6.2","3.0.0","3.0.1","3.1.0","3.1.1","3.2.0","4.0.0","4.1.0","4.2.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/h2/PYSEC-2026-1435.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}