mediumCVSS 5.6Vulnerability

CVE-2026-84380

### Summary HTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence. ### Details When a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present. For example: ```python import httpx2 request = httpx2.Request( "POST", "http://example.com/", headers={"Transfer-Encoding": "chunked"}, content=b"test 123", ) print(request.headers) ``` The request contains both: ```text Transfer-Encoding: chunked Content-Length: 8 ``` On an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path. Streaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction. ### Impact An attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop. Depending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent

Properties

severity
medium
summary
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
epss_score
0.00221
cvss_score
5.6
ghsa_published
2026-09-08T20:46:28Z
source_url
https://github.com/advisories/GHSA-pf96-p4fj-6566
ghsa_updated
2026-09-08T20:46:28Z
ghsa_id
GHSA-pf96-p4fj-6566
cve_id
CVE-2026-84380
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.12542

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/httpx2

AFFECTS (1)

[Software]pip/httpx2

HAS_WEAKNESS (1)

[Weakness]Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84380 (CVSS 5.6) — Ninja Signal Threat Intelligence | Ninja Signal