{"id":"PYSEC-2026-3846","summary":"HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)","details":"### Summary\n\nWhen decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streamed the response to keep memory usage bounded.\n\n### Details\n\nHTTPX2's default transport reads the socket in pieces of up to 64 KiB. Before `2.12.0`, each piece was inflated completely into one intermediate allocation before any decompressed bytes were yielded.\n\nAt DEFLATE's maximum compression ratio of roughly 1032:1, a 64 KiB compressed chunk can expand to about 64 MiB in one allocation. Brotli and Zstandard responses can cause similarly large amplification. Streaming the response did not prevent these transient allocations.\n\n### Impact\n\nApplications that fetch resources from untrusted or attacker-influenced servers - such as webhook receivers, link unfurlers, crawlers, SSRF-reachable fetchers, and redirect followers - can experience memory pressure or out-of-memory termination when processing a malicious compressed response. No authentication or user interaction is required beyond issuing a request to the server.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.12.0` or later. Patched versions decompress responses incrementally with bounded intermediate buffers, including responses with multiple content encodings.","aliases":["CVE-2026-84382","GHSA-8xx6-hgc6-gc2m"],"modified":"2026-09-10T12:15:05.042801702Z","published":"2026-09-10T09:45:01.110644Z","references":[{"type":"WEB","url":"https://github.com/pydantic/httpx2/security/advisories/GHSA-8xx6-hgc6-gc2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84382"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/pull/1126"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8"},{"type":"PACKAGE","url":"https://github.com/pydantic/httpx2"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/releases/tag/v2.12.0"},{"type":"PACKAGE","url":"https://pypi.org/project/httpx2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8xx6-hgc6-gc2m"}],"affected":[{"package":{"name":"httpx2","ecosystem":"PyPI","purl":"pkg:pypi/httpx2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.0"}]}],"versions":["0.0.0","2.0.0","2.0.0b1","2.1.0","2.10.0","2.11.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/httpx2/PYSEC-2026-3846.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}