All 5 CVE vulnerabilities found in httpx2, with AI-generated Chinese analysis, references, and POCs.
Vendor: pydantic
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84382 | HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification) CWE-409 | 7.5 | High | 2026-09-02 |
| CVE-2026-84381 | HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies CWE-319 | 8.1 | High | 2026-09-02 |
| CVE-2026-84380 | HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated CWE-444 | 5.6 | Medium | 2026-09-02 |
| CVE-2026-84379 | HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers CWE-93 | 5.3 | Medium | 2026-09-02 |
| CVE-2026-84378 | HTTPX2: Quadratic SSE line buffering can cause CPU denial of service CWE-407 | 5.9 | Medium | 2026-09-02 |
All 5 known CVE vulnerabilities affecting httpx2 with full Chinese analysis, references, and POCs where available.