CVE-2026-71554 is an HTTP request-smuggling vulnerability in the pure-Python HTTP/2 protocol-stack implementation h2. Versions through 4.4.0 accept HTTP/2 request header blocks containing multiple Host headers and forward all supplied Host values to the consuming application. When that application converts the request from HTTP/2 to HTTP/1.1, the converted request can contain multiple Host header lines, creating an HTTP request-smuggling primitive. h2 version 4.4.1 corrects this behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone proof-of-concept for CVE-2026-71554 affecting python-hyper h2 <= 4.4.0. It contains two files: a README documenting the vulnerability, impact conditions, and fix; and a single executable Python PoC, poc_h2_duplicate_host.py. The script uses the h2 library locally to simulate both client and server processing of crafted HTTP/2 headers. Its core function, drive(), sends attacker-controlled header lists through h2.connection.H2Connection objects and returns the RequestReceived headers that the server-side application would observe. A helper, serialise_h1(), then renders those headers into a naive HTTP/1.1 request to illustrate downgrade-boundary behavior. The exploit capability is not remote code execution; it is a request-smuggling/routing-desynchronization primitive. Specifically, the PoC demonstrates that vulnerable h2 accepts duplicate Host headers and forwards them downstream. In the stealth case, :authority is set to match only the last Host header, satisfying h2's validation, while an attacker-controlled first Host header remains visible to downstream components that use first-value semantics. This can cause disagreement between what the HTTP/2 layer validated and what an HTTP/1.1 backend routes on. The script includes three scenarios: duplicate Host without :authority, stealth duplicate Host with :authority bypass, and a control case showing that a single mismatched Host is correctly rejected. There are no live network callbacks, hardcoded IPs, or external command execution. The only external references are documentation/fix URLs and example hostnames used to model routing behavior. The repository is a genuine PoC exploit demonstrating a web/network attack vector under specific deployment conditions, rather than a scanner or detection-only script.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability affecting the python313-h2 package on openSUSE 16.0. The provided CVSS v3 vector indicates network-accessible exploitation with low complexity, no privileges or user interaction required, and low impact to availability only.
A HTTP/2 request-smuggling vulnerability in the pure-Python h2 HTTP/2 protocol-stack library. Affected versions accept and forward multiple Host headers; HTTP/2-to-HTTP/1.1 downgrade handling can produce duplicate Host headers and enable request smuggling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.