shield Security update for python-h2
SUSE-SLE-Module-Python3-15-SP7-2026-3970


This update for python-h2 fixes the following issue: - CVE-2026-71554: duplicate `Host` headers are accepted and forwarded to consuming applications, which can lead to request smuggling (bsc#1274386).

  • Release Date
    Sep 4 2026
  • References
    Bugzilla: 1274386
    CVEs: CVE-2026-71554
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

Python 3 Module 15.7 ppc64le
  • Packages
    python-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock src
    python311-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock rpm
Python 3 Module 15.7 x86_64
  • Packages
    python-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock src
    python311-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock rpm
Python 3 Module 15.7 s390x
  • Packages
    python-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock src
    python311-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock rpm
Python 3 Module 15.7 aarch64
  • Packages
    python-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock src
    python311-h2
    HTTP/2 State-Machine based protocol implementation
    4.1.0-150400.8.9.1 lock rpm