Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84381

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.

A flaw was found in httpcore2, a component used by HTTPX2. When a remote origin uses WebSocket Secure (wss) through a SOCKS5 proxy, httpcore2 fails to initiate Transport Layer Security (TLS) encryption because its upgrade condition only recognizes HTTPS. This vulnerability allows an attacker controlling or observing the proxy path to intercept and read sensitive WebSocket traffic, including authentication details and data frames, as it is transmitted in plaintext. The attacker could also modify the traffic or impersonate the WebSocket server, leading to information disclosure and potential compromise of communication integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-automl-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2527704httpx2: httpcore2: HTTPX2: WebSocket traffic sent in plaintext via SOCKS5 proxy due to TLS failure

EPSS

Процентиль: 0%
0.00079
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
13 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.

CVSS3: 8.1
nvd
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.

CVSS3: 8.1
debian
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, h ...

CVSS3: 8.1
github
8 дней назад

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

EPSS

Процентиль: 0%
0.00079
Низкий

8.1 High

CVSS3