httpx2 has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.8 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-84382High· 7.5HTTPX2 is a next generation HTTP client for Python41CVE-2026-84378Medium· 5.9HTTPX2 is a next generation HTTP client for Python33CVE-2026-84380Medium· 5.6HTTPX2 is a next generation HTTP client for Python31CVE-2026-84379Medium· 5.3HTTPX2 is a next generation HTTP client for Python29
httpx2 vulnerabilities
CVEs affecting httpx2, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-84382High· 7.5HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…
CVE-2026-84380Medium· 5.6HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…
CVE-2026-84379Medium· 5.3HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…
CVE-2026-84378Medium· 5.9HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-contr…