THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8xx6-hgc6-gc2m (high) — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

[GHSA] GHSA-8xx6-hgc6-gc2m (high) — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

medgithub_advisoriesPublished 2026-09-08

GHSA-8xx6-hgc6-gc2m Severity: high CVE: CVE-2026-84382

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

### Summary

When decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermedia

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8xx6-hgc6-gc2m