Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84380

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 5.6

Описание

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This issue is fixed in version 2.11.0.

A flaw was found in HTTPX2, a Python HTTP client. The Request._prepare() function can incorrectly add a Content-Length header to a request that already includes a Transfer-Encoding header. This conflict in HTTP framing headers can lead to request smuggling or connection desynchronization. This could allow an attacker to bypass security controls or interfere with network traffic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-automl-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2527695httpx2: HTTPX2: Request Smuggling and Connection Desynchronization via Conflicting HTTP Headers

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
13 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This issue is fixed in version 2.11.0.

CVSS3: 5.6
nvd
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This issue is fixed in version 2.11.0.

CVSS3: 5.6
debian
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, R ...

CVSS3: 5.6
github
8 дней назад

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

5.6 Medium

CVSS3