Sploitus

CVE-2025-57804

No indexed exploits for CVE-2025-57804 yet

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.

Affected products
Debian, Suse, H2
Fix
Available
CVSS 4.0
6.9 MEDIUM
EPSS
1.7% (75th percentile)
Weakness
CWE-93
NVD status
Deferred
Published
2025-08-25
CVE-2025-57804 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-57804 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-57804 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.