{"id":"GHSA-847f-9342-265h","summary":"h2 allows HTTP Request Smuggling due to illegal characters in headers","details":"### Summary\n\nHTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls.","aliases":["CVE-2025-57804","PYSEC-2026-1435"],"modified":"2026-07-17T21:14:39.540215558Z","published":"2025-08-25T20:44:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-08-25T20:44:43Z","nvd_published_at":"2025-08-25T21:15:37Z","cwe_ids":["CWE-93"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57804"},{"type":"WEB","url":"https://github.com/python-hyper/h2/commit/035e9899f95e3709af098f578bfc3cd302298e3a"},{"type":"PACKAGE","url":"https://github.com/python-hyper/h2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00004.html"}],"affected":[{"package":{"name":"h2","ecosystem":"PyPI","purl":"pkg:pypi/h2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0"}]}],"versions":["0.1.0","1.0.0","1.1.0","1.1.1","2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.6.2","3.0.0","3.0.1","3.1.0","3.1.1","3.2.0","4.0.0","4.1.0","4.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-847f-9342-265h/GHSA-847f-9342-265h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}