<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:13:04 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-71554</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-71554</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-h2, Alpaquita:25: py3-h2, Alpaquita:stream: py3-h2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-h2, Alpaquita:25: py3-h2, Alpaquita:stream: py3-h2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-71554</guid>
    </item>
    <item>
      <title>BREW-bilix-CVE-2026-71554 — h2: Duplicate Host header could facilitate request smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/brew-bilix-cve-2026-71554</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bilix&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bilix&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-bilix-cve-2026-71554</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-VQ36233 — Security fix for CVE-2026-71554 applied in: airflow-3 3.0.6-r4, airflow-3 3.1.8-r8, airflow-3 3.2.1-r7, airflow-3 3.2.2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-vq36233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;CVE-2026-71554 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;CVE-2026-71554 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-vq36233</guid>
    </item>
    <item>
      <title>EUVD-2026-349512</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349512</link>
      <description>EUVD-2026-349512</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349512</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71554</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71554</link>
      <description>&lt;p&gt;h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71554</guid>
    </item>
    <item>
      <title>GHSA-6hr6-w5qg-qmwg — h2: Duplicate Host header could facilitate request smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6hr6-w5qg-qmwg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: h2&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: h2&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6hr6-w5qg-qmwg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11523-1 — python313-h2-4.4.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11523-1</link>
      <description>&lt;p&gt;python313-h2-4.4.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-h2-4.4.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11523-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3628 — h2: Duplicate Host header could facilitate request smuggling</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3628</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: h2&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: h2&lt;/p&gt;
&lt;p&gt;### Impact
h2 &amp;lt;=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444).&lt;/p&gt;
&lt;p&gt;### Patches
Patched and fixed in v4.4.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack.&lt;/p&gt;
&lt;p&gt;### References
Similar to the previously disclosed and fixed duplicate content-length issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3628</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23563-1 — Security update for python-h2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23563-1</link>
      <description>&lt;p&gt;Security update for python-h2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-h2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23563-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-71554</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71554</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-h2, Ubuntu:20.04:LTS: python-h2, Ubuntu:22.04:LTS: python-h2, Ubuntu:24.04:LTS: python-h2, Ubuntu:26.04:LTS: python-h2&lt;/p&gt;
&lt;p&gt;h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-h2, Ubuntu:20.04:LTS: python-h2, Ubuntu:22.04:LTS: python-h2, Ubuntu:24.04:LTS: python-h2, Ubuntu:26.04:LTS: python-h2&lt;/p&gt;
&lt;p&gt;h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71554</guid>
    </item>
  </channel>
</rss>
