PyPI: h2

CVE-2026-71554

Safety vulnerability ID: SFTY-20260806-02568

Affected versions of the `h2` package are vulnerable to Request Smuggling due to improper handling of duplicate Host headers. The `h2` library accepts HTTP/2 request header blocks that contain multiple Host headers and forwards all of them to the consuming application, which may downgrade the request to HTTP/1.1, resulting in two Host headers in the request. An attacker can exploit this vulnerability by crafting requests with multiple Host headers, potentially bypassing security controls or routing requests to unintended destinations.

Created at: Aug 8, 2026Updated at: Aug 8, 2026

Overview

h2: Duplicate Host header could facilitate request smuggling

Advisory

h2 – HTTP Request/Response Smuggling

Affected Package

Affecting h2 package, versions
<= 4.4.0

Also affects

---

How to Fix

Upgrade
h2
to
4.4.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more