Sourced from h2's changelog.
4.4.1 (2026-08-03)
Bugfixes
- Performance improvement: remove consumed frames in-place from data buffer.
- Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.
4.4.0 (2026-07-23)
API Changes (Backward Incompatible)
- Support for Python 3.9 has been removed.
- Support for PyPy 3.9 has been removed.
Stream.end_stream()now raisesNoSuchStreamErrororStreamClosedErrorexceptions, instead of a genericKeyError.- Duplicate
content-lengthheaders with different values now raiseProtocolError. Previously, the firstcontent-lengthheader was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.- Parse
content-lengthheaders according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.- backfill from v4.3.0 Convert emitted events into Python
dataclass, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.API Changes (Backward Compatible)
- Support for Python 3.14 has been added.
H2Connection.receive_datanow accepts any byte-like object that implements the buffer protocol, such asbytes,bytearray, andmemoryview. Existingbytescallers are unaffected.- Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires
:method=CONNECTand:authority, and forbids:scheme/:path. Extended CONNECT (e.g., WebSocket) requires:scheme,:path,:authorityplus:protocol. (PR #1309)- Fix incorrect substring matching of secure header in
cookieand:method.Bugfixes
- Fix to allow sending 0 bytes on a stream even if the flow control window is negative.
- Reject non-zero
SETTINGS_ENABLE_PUSHvalues received from servers.
bc239af
v4.4.192b925e
add test for duplicate host headers292a408
reject duplicate Host headers in request headers04d3b87
update changelog439b970
prepare for next release cycle9a7ff74
performance: remove consumed frames in place from data buffer (#1321)6cce763
v4.4.0dfafda3
Bump pytest from 8.4.2 to 9.0.3 (#1320)b45207c
dependencies and packaging++c40145f
parse content-length headers according to RFC9110 grammar
for numbers (1*DI...Sourced from h2's changelog.
4.4.1 (2026-08-03)
Bugfixes
- Performance improvement: remove consumed frames in-place from data buffer.
- Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.
4.4.0 (2026-07-23)
API Changes (Backward Incompatible)
- Support for Python 3.9 has been removed.
- Support for PyPy 3.9 has been removed.
Stream.end_stream()now raisesNoSuchStreamErrororStreamClosedErrorexceptions, instead of a genericKeyError.- Duplicate
content-lengthheaders with different values now raiseProtocolError. Previously, the firstcontent-lengthheader was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.- Parse
content-lengthheaders according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.- backfill from v4.3.0 Convert emitted events into Python
dataclass, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.API Changes (Backward Compatible)
- Support for Python 3.14 has been added.
H2Connection.receive_datanow accepts any byte-like object that implements the buffer protocol, such asbytes,bytearray, andmemoryview. Existingbytescallers are unaffected.- Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires
:method=CONNECTand:authority, and forbids:scheme/:path. Extended CONNECT (e.g., WebSocket) requires:scheme,:path,:authorityplus:protocol. (PR #1309)- Fix incorrect substring matching of secure header in
cookieand:method.Bugfixes
- Fix to allow sending 0 bytes on a stream even if the flow control window is negative.
- Reject non-zero
SETTINGS_ENABLE_PUSHvalues received from servers.
bc239af
v4.4.192b925e
add test for duplicate host headers292a408
reject duplicate Host headers in request headers04d3b87
update changelog439b970
prepare for next release cycle9a7ff74
performance: remove consumed frames in place from data buffer (#1321)6cce763
v4.4.0dfafda3
Bump pytest from 8.4.2 to 9.0.3 (#1320)b45207c
dependencies and packaging++c40145f
parse content-length headers according to RFC9110 grammar
for numbers (1*DI...Sourced from h2's changelog.
4.4.1 (2026-08-03)
Bugfixes
- Performance improvement: remove consumed frames in-place from data buffer.
- Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.
4.4.0 (2026-07-23)
API Changes (Backward Incompatible)
- Support for Python 3.9 has been removed.
- Support for PyPy 3.9 has been removed.
Stream.end_stream()now raisesNoSuchStreamErrororStreamClosedErrorexceptions, instead of a genericKeyError.- Duplicate
content-lengthheaders with different values now raiseProtocolError. Previously, the firstcontent-lengthheader was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.- Parse
content-lengthheaders according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.- backfill from v4.3.0 Convert emitted events into Python
dataclass, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.API Changes (Backward Compatible)
- Support for Python 3.14 has been added.
H2Connection.receive_datanow accepts any byte-like object that implements the buffer protocol, such asbytes,bytearray, andmemoryview. Existingbytescallers are unaffected.- Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires
:method=CONNECTand:authority, and forbids:scheme/:path. Extended CONNECT (e.g., WebSocket) requires:scheme,:path,:authorityplus:protocol. (PR #1309)- Fix incorrect substring matching of secure header in
cookieand:method.Bugfixes
- Fix to allow sending 0 bytes on a stream even if the flow control window is negative.
- Reject non-zero
SETTINGS_ENABLE_PUSHvalues received from servers.
bc239af
v4.4.192b925e
add test for duplicate host headers292a408
reject duplicate Host headers in request headers04d3b87
update changelog439b970
prepare for next release cycle9a7ff74
performance: remove consumed frames in place from data buffer (#1321)6cce763
v4.4.0dfafda3
Bump pytest from 8.4.2 to 9.0.3 (#1320)b45207c
dependencies and packaging++c40145f
parse content-length headers according to RFC9110 grammar
for numbers (1*DI...