CyberRota Analysis
AI-GeneratedHTTPX2 versions prior to 2.11.0 are vulnerable to a request smuggling and connection desynchronization issue due to improper handling of the Content-Length and Transfer-Encoding headers in the Request._prepare() method. This flaw allows attackers to exploit discrepancies between upstream and downstream intermediaries, potentially leading to unauthorized data access or service disruptions. Organizations using HTTPX2 for Python should prioritize upgrading to version 2.11.0 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This issue is fixed in version 2.11.0.