ALT-PU-2025-8957-3
Package python3-module-h11 updated to version 0.16.0-alt1 for branch sisyphus in task 388872.
Closed vulnerabilities
Modified: 2026-03-04
BDU:2025-06251
Уязвимость библиотеки h11, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации
Modified: 2026-04-15
CVE-2025-43859
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.
Modified: 2025-04-25
GHSA-vqfr-h8mv-ghfj
h11 accepts some malformed Chunked-Encoding bodies
Closed bugs
CVE-2025-43859 in python-module-h11 0.14
