CVE-2025-57804 - CVE House
Back to Database
Status published Medium CVE-2025-57804

h2 allows HTTP Request Smuggling due to illegal characters in headers

Vulnerability Description

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-57804

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

python-hyper

View all reports →

Affected Software

h2
Vulnerable Versions:
< 4.3.0

Timeline

Official Publish: August 25th, 2025
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.