Fixes the following security issue:
- CVE-2025-43859: A leniency in h11's parsing of line terminators in
chunked-coding message bodies can lead to request smuggling
vulnerabilities under certain conditions.
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-43859
- 114803a29c
For more details on the version bump, see:
- https://github.com/python-hyper/h11/compare/v0.14.0...v0.16.0
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 6541717ef9)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
6 lines
321 B
Plaintext
6 lines
321 B
Plaintext
# md5, sha256 from https://pypi.org/pypi/h11/json
|
|
md5 af51401a776fd654cfd98a197af9f21f h11-0.16.0.tar.gz
|
|
sha256 4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208ee5ff1 h11-0.16.0.tar.gz
|
|
# Locally computed sha256 checksums
|
|
sha256 37db5bb85926db28a427a25867f10b1232003aea1be69ccb851138adb8e6f361 LICENSE.txt
|