h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-h11 | May 15, 2025 | Apr 24, 2025 |
| Freebsd | — | Upgrade py310-h11Upgrade py311-h11Upgrade py312-h11Upgrade py39-h11 | Apr 30, 2025 | Apr 29, 2025 |
| Suse | — | Upgrade python311-h11Upgrade python313-h11 | Dec 5, 2025 | May 2, 2025 |
| Ubuntu | — | Upgrade python3-h11 | May 9, 2025 | Apr 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub