Zetlyn

httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification

cve CVE-2026-84382 1 source, 1 claim · Watch

Red Hat writes:
httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification the claim

What each source says

PropertySourceSaidMeans here
Cvss
cvss
Red Hat7.5
receipt
Source
Red Hat
Its words
7.5
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84382",
  "CWE": "CWE-409",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2527702",
  "bugzilla_description": "httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T18:03:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84382.json",
  "severity": "important"
}
—
Cwe
cwe
Red HatCWE-409
receipt
Source
Red Hat
Its words
CWE-409
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84382",
  "CWE": "CWE-409",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2527702",
  "bugzilla_description": "httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T18:03:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84382.json",
  "severity": "important"
}
—
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84382",
  "CWE": "CWE-409",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2527702",
  "bugzilla_description": "httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T18:03:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84382.json",
  "severity": "important"
}
high

vulnerability

httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification
zetlyn/cve-redhat · 2026-09-02
cvss 7.5 cwe CWE-409 severity important source