h2 has 3 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 5.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- h2 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
h2 vulnerabilities
CVEs affecting h2, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
RUSTSEC-2026-0258Noneh2 unbounded empty DATA frames
h2 unbounded empty DATA frames
▾ Sunlith2 · h2via OSV
CVE-2026-71554Medium· 5.3PoCh2 is a pure-Python implementation of a HTTP/2 protocol stack
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the co…
▾ Twilighth2 · h2EPSS 0.44%via NVD
CVE-2025-57804Mediumh2 allows HTTP Request Smuggling due to illegal characters in headers
h2 allows HTTP Request Smuggling due to illegal characters in headers
▾ Sunlith2 · h2EPSS 1.7%via OSV