ALT-PU-2025-8979-1
Package python3-module-h11 updated to version 0.16.0-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Published: 2025-04-24
BDU:2025-06251
Уязвимость библиотеки h11, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации
Severity: CRITICAL (9.1)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: CRITICAL (9.4)
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:N
References:
Published: 2025-04-24
Modified: 2025-04-29
Modified: 2025-04-29
CVE-2025-43859
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.
Severity: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
Closed bugs
CVE-2025-43859 in python-module-h11 0.14