{"id":"GHSA-63cx-g855-hvv4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-63cx-g855-hvv4","summary":"mitmproxy binaries embed a vulnerable python-hyper/h2 dependency","details":"mitmproxy 12.1.1 and below embed python-hyper/h2 ≤ v4.2.0, which has a gap in its HTTP/2 header validation. This enables request smuggling attacks when mitmproxy is in a configuration where it translates HTTP/2 to HTTP/1. For example, this affects reverse proxies to `http://` backends. It does not affect mitmproxy's regular mode.\n\nAll users are encouraged to upgrade to mitmproxy 12.1.2, which includes a fixed version of h2.\n\nMore details about the vulnerability itself can be found at https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h.","published":"2025-08-25T21:01:00Z","modified":"2026-09-10T03:50:26.707538775Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mitmproxy","fixedVersion":"12.1.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-63cx-g855-hvv4"},{"type":"WEB","url":"https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h"},{"type":"PACKAGE","url":"https://github.com/mitmproxy/mitmproxy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:26.707538775Z"}}