PyPI: h2
CVE-2026-71554
Safety vulnerability ID: SFTY-20260806-02568
Affected versions of the `h2` package are vulnerable to Request Smuggling due to improper handling of duplicate Host headers. The `h2` library accepts HTTP/2 request header blocks that contain multiple Host headers and forwards all of them to the consuming application, which may downgrade the request to HTTP/1.1, resulting in two Host headers in the request. An attacker can exploit this vulnerability by crafting requests with multiple Host headers, potentially bypassing security controls or routing requests to unintended destinations.
Overview
h2: Duplicate Host header could facilitate request smuggling
Advisory
h2 – HTTP Request/Response Smuggling
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
