CVE-2025-57804

EUVD-2025-28631
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 75.93%
Debian logo
Debian Releases
Debian Product
Codename
python-h2
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
4.0.0-3+deb11u1
fixed
forky
4.3.0-2
fixed
sid
4.3.0-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-h2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python3-h2
suse enterprise server 15 SP4
3.2.0-150200.3.5.1
fixed
python311-h2
suse enterprise server 15 SP4
4.1.0-150400.8.6.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-h2
Amazon Linux 2023
0:4.0.0-2.amzn2023.0.4
fixed