CVE-2026-71554: h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward eve
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71554
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71554 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for h2 is a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumGHSA-6hr6-w5qg-qmwg: h2: Duplicate Host header could facilitate request smugglingghsa · 2026-08-06
- criticalCVE-2026-67208: Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticate…nvd · 2026-07-30
- criticalCVE-2026-59827: Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15…nvd · 2026-07-09
- criticalCVE-2026-59826: Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 unti…nvd · 2026-07-09
- criticalCVE-2026-41042: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, whi…nvd · 2026-07-08
- unknownCVE-2026-55633: DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of…nvd · 2026-07-07
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06