httpx2
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting httpx2page 1 of 1
- CVE-2026-84378MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.10.02026-09-02
vulnerable: 2.5.0 ... 2.9.1 (6 versions)
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-control…
- CVE-2026-84379MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.11.02026-09-02
vulnerable: 0.0.0 ... 2.9.1 (14 versions)
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-eleme…
- CVE-2026-84380MEDIUMCVSS 5.6EG 5.6✓ Fixed in 2.11.02026-09-02
vulnerable: 0.0.0 ... 2.9.1 (14 versions)
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding hea…
- CVE-2026-84381HIGHCVSS 8.1EG 8.1✓ Fixed in 2.10.02026-09-02
vulnerable: 2.6.0, 2.7.0, 2.8.0, 2.9.0, 2.9.1
HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a S…
- CVE-2026-84382HIGHCVSS 7.5EG 7.5✓ Fixed in 2.12.02026-09-02
vulnerable: 0.0.0 ... 2.9.1 (15 versions)
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields boun…
Check whether httpx2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for httpx2 CVEs against the assets you own.
Start Free Scan →