SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84378

MEDIUM · CVSS 5.9 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The HTTPX2 library versions 2.5.0 to 2.10.0 are vulnerable to a denial-of-service condition due to inefficient handling of Server-Sent Events (SSE) in the `_SSELineDecoder.decode()` function, which can lead to excessive CPU consumption when processing maliciously crafted streams. This vulnerability can significantly impact applications relying on the HTTPX2 client for SSE, potentially blocking synchronous workers or asynchronous event loops. Developers and organizations using affected versions should prioritize upgrading to version 2.10.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84378
Severity
MEDIUM
CVSS
5.9
EPSS
0.32%

Original NVD Description

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many response chunks. The behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the total processing work grows quadratically with the line length, allowing a crafted stream to consume excessive CPU and block a synchronous worker or asynchronous event loop. This issue is fixed in version 2.10.0.