Vendor
A proof-of-concept exploit has been released for CVE-2026-71554, a request smuggling vulnerability in the h2 Python library that allows for potential denial-of-service via duplicate Host headers.