Data Amplification Affecting httpx2 package, versions [,2.12.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.63% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-HTTPX2-20361663
  • published1 Oct 2026
  • disclosed8 Sept 2026
  • creditHiroki Nishino

Introduced: 8 Sep 2026

NewCVE-2026-84382  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

Upgrade httpx2 to version 2.12.0 or higher.

Overview

httpx2 is a The next generation HTTP client.

Affected versions of this package are vulnerable to Data Amplification in the default transport's response decompression, which inflates each network read of up to 64 KiB completely into a single intermediate allocation before yielding any decompressed bytes, across the gzip, deflate, brotli, and zstandard encodings. An attacker can exhaust the client's memory and terminate the process by serving a compressed response at a ratio reaching 1032:1, so each chunk read expands to roughly 64 MiB in one allocation. This requires the application to fetch responses from a server the attacker controls or can influence, which puts webhook receivers, link unfurlers, crawlers, fetchers reachable through SSRF, and redirect followers in scope.

CVSS Base Scores

version 4.0
version 3.1