TopVuln

High-risk vulnerability digests

CVE-2025-57804

  • MEDIUM

Security Bulletin: Multiple vulnerabilities in IBM Observability with Instana (OnPrem)

Details

CVSS v3
9.8
CVSS v4
6.9
NVD published
2025-08-25 21:15:37
EPSS
<0.1% probability · 22.9th percentile — 2026-03-16
Affected versions
Not available in our cache.
Summary
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling attacks by injecting CRLF characters into headers. This occurs when servers downgrade HTTP/2 requests to HTTP/1.1 without properly validating header names/values, enabling attackers to manipulate request boundaries and bypass security controls. This issue has been patched in version 4.3.0.
Remediation
Not available in our cache.
Exploit info
Not available in our cache.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.