CyberRota Analysis
AI-GeneratedThe HTTPX2 library versions 2.5.0 to 2.10.0 are vulnerable to a denial-of-service condition due to inefficient handling of Server-Sent Events (SSE) in the `_SSELineDecoder.decode()` function, which can lead to excessive CPU consumption when processing maliciously crafted streams. This vulnerability can significantly impact applications relying on the HTTPX2 client for SSE, potentially blocking synchronous workers or asynchronous event loops. Developers and organizations using affected versions should prioritize upgrading to version 2.10.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many response chunks. The behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the total processing work grows quadratically with the line length, allowing a crafted stream to consume excessive CPU and block a synchronous worker or asynchronous event loop. This issue is fixed in version 2.10.0.