Security Issue: Update h11 Package in httpx to >=0.16.0 Due to Malformed Chunked-Encoding Vulnerability #3560
Replies: 1 comment 3 replies
-
|
This has been raised. We're open to serious conversations only. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary:
It has come to my attention that httpx currently uses an outdated version of the h11 package, which is vulnerable to malformed Chunked-Encoding bodies. This vulnerability has been addressed in h11 version >=0.16.0 and poses a security risk.
According to the advisory GHSA-vqfr-h8mv-ghfj, the earlier versions of h11 are vulnerable to malformed Chunked-Encoding bodies.
Current Situation:
httpcore (which httpx depends on) has already upgraded its dependency on h11 to >=0.16.0, addressing the issue.
However, httpx has not yet upgraded to a safe version of h11.
Suggested Approach:
I suggest updating the h11 dependency in the httpx package to >=0.16.0, which will resolve this vulnerability and bring it in line with httpcore.
Impact:
The issue is marked as a security vulnerability, and this update is critical for ensuring the safety and integrity of httpx users.
Failing to upgrade may expose applications using httpx to potential exploits due to the Chunked-Encoding vulnerability in earlier versions of h11.
Additional Information:
httpcore already uses httpx, which in turn uses h11. httpcore has successfully upgraded to h11 >=0.16.0.
httpx should follow suit to ensure compatibility and security.
Please consider marking this issue as important and addressing it with a high priority, given the security implications.
Beta Was this translation helpful? Give feedback.
All reactions