THREAT OPS › Threat News › [GHSA] GHSA-8xx6-hgc6-gc2m (high) — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
[GHSA] GHSA-8xx6-hgc6-gc2m (high) — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
GHSA-8xx6-hgc6-gc2m Severity: high CVE: CVE-2026-84382
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
### Summary
When decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermedia
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- CVE-2026-84382cve
Original source: https://github.com/advisories/GHSA-8xx6-hgc6-gc2m