The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade httpx2 to version 2.12.0 or higher.
httpx2 is a The next generation HTTP client.
Affected versions of this package are vulnerable to Data Amplification in the default transport's response decompression, which inflates each network read of up to 64 KiB completely into a single intermediate allocation before yielding any decompressed bytes, across the gzip, deflate, brotli, and zstandard encodings. An attacker can exhaust the client's memory and terminate the process by serving a compressed response at a ratio reaching 1032:1, so each chunk read expands to roughly 64 MiB in one allocation. This requires the application to fetch responses from a server the attacker controls or can influence, which puts webhook receivers, link unfurlers, crawlers, fetchers reachable through SSRF, and redirect followers in scope.