CVE-2025-43859

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 444

Summary

CVE-2025-43859 affects the Python implementation of HTTP/1.1 named h11. The vulnerability arises from h11's lenient parsing of line terminators in chunked-coding message bodies, which can result in request smuggling under specific conditions. Exploitation of this issue requires both a buggy h11 and a susceptible (reverse) proxy, making it dependent on both components. Version 0.16.0 of h11 has been released with the necessary patch to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share