SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84380

MEDIUM · CVSS 5.6 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

HTTPX2 versions prior to 2.11.0 are vulnerable to a request smuggling and connection desynchronization issue due to improper handling of the Content-Length and Transfer-Encoding headers in the Request._prepare() method. This flaw allows attackers to exploit discrepancies between upstream and downstream intermediaries, potentially leading to unauthorized data access or service disruptions. Organizations using HTTPX2 for Python should prioritize upgrading to version 2.11.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84380
Severity
MEDIUM
CVSS
5.6
EPSS
0.22%

Original NVD Description

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This issue is fixed in version 2.11.0.