{"id":"PYSEC-2026-3849","summary":"HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated","details":"### Summary\n\nHTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection desynchronization when processed by intermediaries that disagree about which header takes precedence.\n\n### Details\n\nWhen a request body has a known size, HTTPX2's content encoder returns a default `Content-Length`. `Request._prepare()` applies each default header with `setdefault()`, which only checks whether that same header is already present. It does not check whether the mutually exclusive `Transfer-Encoding` header is present.\n\nFor example:\n\n```python\nimport httpx2\n\nrequest = httpx2.Request(\n    \"POST\",\n    \"http://example.com/\",\n    headers={\"Transfer-Encoding\": \"chunked\"},\n    content=b\"test 123\",\n)\n\nprint(request.headers)\n```\n\nThe request contains both:\n\n```text\nTransfer-Encoding: chunked\nContent-Length: 8\n```\n\nOn an HTTP/1.1 connection, the body is serialized using chunked transfer coding while both headers are sent on the wire. This violates HTTP message-framing requirements. Fixed-size byte, JSON, form, and known-length multipart bodies can reach the affected path.\n\nStreaming bodies with an explicit `Content-Length` are not affected in current HTTPX2 releases because the automatically generated `Transfer-Encoding` is already suppressed in that direction.\n\n### Impact\n\nAn attacker may be able to use the conflicting framing headers as a request-smuggling or desynchronization primitive. Exploitation requires an application to pass attacker-controlled request framing headers and associated body data to HTTPX2, use HTTP/1.1, and communicate through a proxy or origin that accepts conflicting headers and interprets them differently from another hop.\n\nDepending on the downstream infrastructure, successful exploitation could interfere with requests sharing a persistent connection, bypass front-end routing or authorization decisions, or poison responses or caches. Applications that do not forward attacker-controlled `Transfer-Encoding` headers are not directly exposed.\n\n### Mitigation\n\nUpgrade to HTTPX2 `2.11.0` or later. Patched versions treat `Content-Length` and `Transfer-Encoding` as mutually exclusive when applying automatically generated request headers.\n\nIf upgrading is not immediately possible, remove `Transfer-Encoding` and other hop-by-hop framing headers from untrusted input before constructing outbound requests. Applications acting as proxies should derive outbound framing from the body rather than forwarding inbound `Content-Length` or `Transfer-Encoding` headers.","aliases":["CVE-2026-84380","GHSA-pf96-p4fj-6566"],"modified":"2026-09-10T12:15:06.096986959Z","published":"2026-09-10T09:45:01.065667Z","references":[{"type":"WEB","url":"https://github.com/pydantic/httpx2/security/advisories/GHSA-pf96-p4fj-6566"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84380"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/pull/1137"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab"},{"type":"PACKAGE","url":"https://github.com/pydantic/httpx2"},{"type":"WEB","url":"https://github.com/pydantic/httpx2/releases/tag/v2.11.0"},{"type":"PACKAGE","url":"https://pypi.org/project/httpx2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pf96-p4fj-6566"}],"affected":[{"package":{"name":"httpx2","ecosystem":"PyPI","purl":"pkg:pypi/httpx2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.0"}]}],"versions":["0.0.0","2.0.0","2.0.0b1","2.1.0","2.10.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/httpx2/PYSEC-2026-3849.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}