CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71554

mediumCVSS 5.3covered by 2 sourcesfirst seen 2026-08-06
Impact h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444). Patches Patched and fixed in v4.4.1 Workarounds Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack. References Similar to the previously disclosed and fixed duplicate content-length issue.

⚡ Watch CVE-2026-71554

Get an email if CVE-2026-71554 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-71554

CVE.org record

Embed the live status

CVE-2026-71554 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71554 status](https://www.csirts.com/badge/CVE-2026-71554)](https://www.csirts.com/cve/CVE-2026-71554)