ALT-PU-2025-8988-1

Package update python3-module-h11 in branch sisyphus_loongarch64

Version0.16.0-alt1
Task#0
Published2025-07-04
Max severityCRITICAL
Severity:

Closed issues (2)

BDU:2025-06251
CRITICAL9.1

Уязвимость библиотеки h11, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

Published: 2025-06-02Modified: 2026-03-04
CVSS 3.xCRITICAL 9.1
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.0CRITICAL 9.4
CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:N
References
CVE-2025-43859
CRITICAL9.1

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.

Published: 2025-04-24Modified: 2026-04-15
CVSS 3.xCRITICAL 9.1
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Closed bugs (1)

CVE-2025-43859 in python-module-h11 0.14