CVE-2025-43859

Published Apr 24, 2025

Last updated 14 hours ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-43859 is a vulnerability found in h11, a Python implementation of HTTP/1.1, specifically in versions prior to 0.16.0. The vulnerability stems from a leniency in how h11 parses line terminators within chunked-coding message bodies. This can lead to request smuggling attacks under certain conditions. The vulnerability can be exploited when a buggy h11 implementation is paired with a misconfigured or buggy reverse proxy. The issue has been addressed in h11 version 0.16.0. Fixing either the h11 component or the proxy component can mitigate the risk.

Description
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-444

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2025-43859 2 - CVE-2025-31324 3 - CVE-2024-27876 4 - CVE-2025-32432 5 - CVE-2025-29306 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. PythonのHTTPライブラリh11にリクエストスマグリングの脆弱性。CVE-2025-43859はCVSSスコア9.1で、誤構成/バグめいたHTTPプロキシとの組み合わせ時に発現。chunkedなメッセージボディにおける行終端文字のパースにおけ

    @__kokumoto

    27 Apr 2025

    781 Impressions

    0 Retweets

    8 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-43859: Request Smuggling Vulnerability in Python’s h11 HTTP Library https://t.co/XMYNNQ30yN

    @the_yellow_fall

    27 Apr 2025

    761 Impressions

    4 Retweets

    18 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-43859 ⚠️🔴 CRITICAL (9.1) 🏢 python-hyper - h11 🏗️ < 0.16.0 🔗 https://t.co/TxlJOTkgEt 🔗 https://t.co/4pL75asJqM #CyberCron #VulnAlert #InfoSec https://t.co/agf5dadkzO

    @cybercronai

    25 Apr 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. おはようございます。早速CVE-2025-43859リクエストスマグリング対応です💤バージョンアップするだけ…

    @sanmamama_

    24 Apr 2025

    511 Impressions

    0 Retweets

    11 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2025-43859 h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to requ… https://t.co/5ch3cUemXC

    @CVEnew

    24 Apr 2025

    394 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-43859: CRITICAL] Update to h11 version 0.16.0 to fix a parsing vulnerability. It could lead to request smuggling with chunked-coding in or out of proxies. Patch mitigates the risk.#cve,CVE-2025-43859,#cybersecurity https://t.co/QpPVMdgYI2 https://t.co/6Xvd0iTRC8

    @CveFindCom

    24 Apr 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes