Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB compressed chunk can expand to approximately 64 MiB in one intermediate allocation, so an attacker-controlled or compromised server can cause severe memory pressure or out-of-memory process termination even when the application streams the response. This issue is fixed in version 2.12.0. | |
| Title | HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification) | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-02T18:03:05.010Z
Reserved: 2026-09-01T16:27:58.130Z
Link: CVE-2026-84382
No data.
Status : Received
Published: 2026-09-02T19:18:08.353
Modified: 2026-09-02T19:18:08.353
Link: CVE-2026-84382
No data.
OpenCVE Enrichment
No data.
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)