Inconsistent interpretation of HTTP requests in h11 - CVE-2025-43859
Published: May 2, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests in h11/_readers.py. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
Fedora
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
IBM Concert Software
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Business Automation Workflow
Ansible Automation Platform
Red Hat OpenStack
Astronomer with IBM
Security QRadar EDR
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM API Connect
python-h11 (Red Hat package)
python-h11
python3-h11 (Ubuntu package)
python-h11-help
python3-h11
python311-h11
python-httpcore
How to mitigate CVE-2025-43859
IBM Concert Software - update to 2.0.0
Astronomer with IBM - update to 1.0.1
IBM Fusion HCI - update to 2.10.0
Security QRadar EDR - update to 3.12.18
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Maximo Application Suite Ai Service - update to 9.0.6
IBM API Connect - update to 10.0.8.2 ifix2
IBM Business Automation Workflow - update to 24.0.0-IF006
python-h11 (Red Hat package) - addressed in versions 0.12.0-2.1.el9ost, 0.12.0-4.el9ost
python-h11 - addressed in versions 0.13.0-2.el8, 0.13.0-2.el9, 0.14.0-7.el10_0, 0.14.0-7.el10_1, 0.14.0-7.fc40, 0.14.0-7.fc41, 0.14.0-7.fc42, 0.16.0-1.fc43
python3-h11 (Ubuntu package) - addressed in versions 0.14.0-1ubuntu0.24.04.1, 0.14.0-1ubuntu0.24.10.1, 0.14.0-1ubuntu0.25.04.1
python-h11 - update to 0.14.0-2
python-h11-help - update to 0.14.0-2
python3-h11 - update to 0.14.0-2
python311-h11 - update to 0.14.0-150400.9.6.1
python-httpcore - update to 1.0.9-1.fc43
Ansible Automation Platform - addressed in versions 2.4, 2.5
Red Hat OpenStack - addressed in versions 17.1, 18.0
External References
Related Security Bulletins
- HTTP request smuggling in Hyper h11
- Fedora 43 update for python-h11, python-httpcore
- Fedora 42 update for python-h11
- Fedora 41 update for python-h11
- Fedora 40 update for python-h11
- Fedora EPEL 9 update for python-h11
- Fedora EPEL 8 update for python-h11
- SUSE update for python-h11
- Fedora EPEL 10.1 update for python-h11
- Fedora EPEL 10.0 update for python-h11
- Ubuntu update for python-h11
- openEuler 24.03 LTS update for python-h11
- openEuler 24.03 LTS SP1 update for python-h11
- Inconsistent interpretation of HTTP requests in Red Hat OpenStack 18.0 packages
- Inconsistent interpretation of HTTP requests in Red Hat OpenStack 17.1 packages
- IBM Maximo Application Suite Ai-Service Component update for h11
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Security QRadar EDR
- IBM Fusion and IBM Fusion HCI update for python package h11
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in IBM Business Automation Workflow
- Astronomer with IBM update for h11 package
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem