以下是该漏洞描述信息的中文翻译: HTTPX2 是一个 Python 的下一代 HTTP 客户端。在 2.11.0 版本之前,位于 中的 方法直接将攻击者可控的 值以及通过 参数传入的自定义头部内容(包括三元素元组 和四元素元组 )直接拼接到 multipart/form-data 部件的头部中,且未对头部名称或值进行验证。 攻击者可利用其中的回车(CR)或换行(LF)字符来提前终止部件头部、注入额外的部件头部,或提前结束部件头部块,从而使得下游的 multipart 解析器将攻击者提供的行视为有效头部,进而改变部
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84381 | 8.1 HIGH | HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies |
| CVE-2026-84382 | 7.5 HIGH | HTTPX2: Streaming response decompression does not bound peak memory (decompression amplifi |
| CVE-2026-84378 | 5.9 MEDIUM | HTTPX2: Quadratic SSE line buffering can cause CPU denial of service |
| CVE-2026-84380 | 5.6 MEDIUM | HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated |
No comments yet