GHSA-63cx-g855-hvv4

Suggest an improvement
Source
https://github.com/advisories/GHSA-63cx-g855-hvv4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-63cx-g855-hvv4/GHSA-63cx-g855-hvv4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-63cx-g855-hvv4
Related
Published
2025-08-25T21:01:00Z
Modified
2026-03-30T14:43:40.850824Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Details

mitmproxy 12.1.1 and below embed python-hyper/h2 ≤ v4.2.0, which has a gap in its HTTP/2 header validation. This enables request smuggling attacks when mitmproxy is in a configuration where it translates HTTP/2 to HTTP/1. For example, this affects reverse proxies to http:// backends. It does not affect mitmproxy's regular mode.

All users are encouraged to upgrade to mitmproxy 12.1.2, which includes a fixed version of h2.

More details about the vulnerability itself can be found at https://github.com/python-hyper/h2/security/advisories/GHSA-847f-9342-265h.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-1395",
        "CWE-444"
    ],
    "github_reviewed_at": "2025-08-25T21:01:00Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / mitmproxy

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.1.2

Affected versions

0.*
0.8
0.8.1
0.9
0.9.1
0.9.2
0.10
0.10.1
0.11
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13
0.14.0
0.15
0.16
0.17
0.18.1
0.18.2
0.18.3
1.*
1.0.0
1.0.1
1.0.2
2.*
2.0.0
2.0.1
2.0.2
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
4.*
4.0.0
4.0.1
4.0.3
4.0.4
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.2
5.3.0
6.*
6.0.0
6.0.1
6.0.2
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
8.*
8.0.0
8.1.0
8.1.1
9.*
9.0.0
9.0.1
10.*
10.0.0
10.1.0
10.1.1
10.1.2
10.1.3
10.1.4
10.1.5
10.1.6
10.2.0
10.2.1
10.2.2
10.2.3
10.2.4
10.3.0
10.3.1
10.4.0
10.4.1
10.4.2
11.*
11.0.0
11.0.1
11.0.2
11.1.0
11.1.2
11.1.3
12.*
12.0.0
12.0.1
12.1.0
12.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-63cx-g855-hvv4/GHSA-63cx-g855-hvv4.json"
last_known_affected_version_range
"<= 12.1.1"