shield
Security update for python-h2
SUSE-SLE-Module-Server-Applications-15-SP7-2026-3972
This update for python-h2 fixes the following issue: - CVE-2026-71554: duplicate `Host` headers are accepted and forwarded to consuming applications, which can lead to request smuggling (bsc#1274386).
-
Release DateSep 4 2026
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
Server Applications Module 15.7 x86_64
-
Packagespython-h2
HTTP/2 State-Machine based protocol implementationpython3-h23.2.0-150200.3.8.1 lock src
HTTP/2 State-Machine based protocol implementation3.2.0-150200.3.8.1 lock rpm
Server Applications Module 15.7 s390x
-
Packagespython-h2
HTTP/2 State-Machine based protocol implementationpython3-h23.2.0-150200.3.8.1 lock src
HTTP/2 State-Machine based protocol implementation3.2.0-150200.3.8.1 lock rpm
Server Applications Module 15.7 aarch64
-
Packagespython-h2
HTTP/2 State-Machine based protocol implementationpython3-h23.2.0-150200.3.8.1 lock src
HTTP/2 State-Machine based protocol implementation3.2.0-150200.3.8.1 lock rpm
Server Applications Module 15.7 ppc64le
-
Packagespython-h2
HTTP/2 State-Machine based protocol implementationpython3-h23.2.0-150200.3.8.1 lock src
HTTP/2 State-Machine based protocol implementation3.2.0-150200.3.8.1 lock rpm