Inconsistent interpretation of HTTP requests in h11 - CVE-2025-43859

 

Inconsistent interpretation of HTTP requests in h11 - CVE-2025-43859

Published: May 2, 2025


Vulnerability identifier: #VU108124
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43859
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests in h11/_readers.py. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

h11
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
Fedora
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
IBM Concert Software
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Business Automation Workflow
Ansible Automation Platform
Red Hat OpenStack
Astronomer with IBM
Security QRadar EDR
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM API Connect
python-h11 (Red Hat package)
python-h11
python3-h11 (Ubuntu package)
python-h11-help
python3-h11
python311-h11
python-httpcore

How to mitigate CVE-2025-43859

Install updates from vendor's website.

h11 - update to 0.16.0
IBM Concert Software - update to 2.0.0
Astronomer with IBM - update to 1.0.1
IBM Fusion HCI - update to 2.10.0
Security QRadar EDR - update to 3.12.18
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Maximo Application Suite Ai Service - update to 9.0.6
IBM API Connect - update to 10.0.8.2 ifix2
IBM Business Automation Workflow - update to 24.0.0-IF006
python-h11 (Red Hat package) - addressed in versions 0.12.0-2.1.el9ost, 0.12.0-4.el9ost
python-h11 - addressed in versions 0.13.0-2.el8, 0.13.0-2.el9, 0.14.0-7.el10_0, 0.14.0-7.el10_1, 0.14.0-7.fc40, 0.14.0-7.fc41, 0.14.0-7.fc42, 0.16.0-1.fc43
python3-h11 (Ubuntu package) - addressed in versions 0.14.0-1ubuntu0.24.04.1, 0.14.0-1ubuntu0.24.10.1, 0.14.0-1ubuntu0.25.04.1
python-h11 - update to 0.14.0-2
python-h11-help - update to 0.14.0-2
python3-h11 - update to 0.14.0-2
python311-h11 - update to 0.14.0-150400.9.6.1
python-httpcore - update to 1.0.9-1.fc43
Ansible Automation Platform - addressed in versions 2.4, 2.5
Red Hat OpenStack - addressed in versions 17.1, 18.0

External References

Related Security Bulletins