highCVSS 7.5Vulnerability

CVE-2026-84382

### Summary When decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded. ### Details HTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded. At DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations. ### Impact Applications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server. ### Mitigation Upgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.

Properties

summary
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
severity
high
epss_score
0.0035
cvss_score
7.5
ghsa_published
2026-09-08T20:48:59Z
source_url
https://github.com/advisories/GHSA-8xx6-hgc6-gc2m
ghsa_updated
2026-09-08T20:48:59Z
ghsa_id
GHSA-8xx6-hgc6-gc2m
cve_id
CVE-2026-84382
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
false
epss_percentile
0.28043

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/httpx2

AFFECTS (1)

[Software]pip/httpx2

HAS_WEAKNESS (1)

[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84382 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal