Httpx2: h2: Duplicate Host header could facilitate request smuggling (CVE-2026-71554)
### Impact h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444). ### Patches Patched and fixed in v4.4.1 ### Workarounds Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack. ### References Similar to the previously disclosed and fixed duplicate content-length issue.
AI Analysis
Technical Summary
CVE-2026-71554 is a vulnerability in python-h2 where duplicate Host headers are accepted and forwarded to consuming applications. This behavior can enable HTTP request smuggling attacks, which may allow an attacker to interfere with the processing of HTTP requests by intermediary devices or servers. The vulnerability has been fixed in an update provided by the SUSE Product Security Team.
Potential Impact
The vulnerability allows an attacker to exploit duplicate Host headers to perform HTTP request smuggling, potentially leading to request interception or manipulation by downstream applications. This can undermine the integrity of HTTP request handling but no known exploits are reported in the wild at this time.
Mitigation Recommendations
An official patch is available for this vulnerability. Users should apply the security update for python-h2 provided by SUSE to remediate the issue. No additional mitigation steps are indicated by the vendor advisory.
Httpx2: h2: Duplicate Host header could facilitate request smuggling (CVE-2026-71554)
Description
### Impact h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-444). ### Patches Patched and fixed in v4.4.1 ### Workarounds Users of the h2 library are advised to check and follow HTTP semantics best practices in their application code. h2 provides best effort sanity checks, but ultimately the calling code is responsible to ensure proper and safe usage of HTTP/2 as provided by h2, hyperframe, and hpack. ### References Similar to the previously disclosed and fixed duplicate content-length issue.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71554 is a vulnerability in python-h2 where duplicate Host headers are accepted and forwarded to consuming applications. This behavior can enable HTTP request smuggling attacks, which may allow an attacker to interfere with the processing of HTTP requests by intermediary devices or servers. The vulnerability has been fixed in an update provided by the SUSE Product Security Team.
Potential Impact
The vulnerability allows an attacker to exploit duplicate Host headers to perform HTTP request smuggling, potentially leading to request interception or manipulation by downstream applications. This can undermine the integrity of HTTP request handling but no known exploits are reported in the wild at this time.
Mitigation Recommendations
An official patch is available for this vulnerability. Users should apply the security update for python-h2 provided by SUSE to remediate the issue. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- CLEANSTART-2026-XL39843
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Alpine"]
- State
- PUBLISHED
Threat ID: 6a7f4430bf8831d53963bc0e
Added to database: 08/14/2026, 16:37:04 UTC
Last enriched: 09/17/2026, 03:16:33 UTC
Last updated: 09/28/2026, 13:47:47 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.