THREAT OPS › Threat News › [GHSA] GHSA-h4x7-gw46-3wm6 (medium) — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
[GHSA] GHSA-h4x7-gw46-3wm6 (medium) — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
GHSA-h4x7-gw46-3wm6 Severity: medium CVE: CVE-2026-84379
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
### Summary
HTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence uploa
Indicators of compromise
- CVE-2026-84379cve
Original source: https://github.com/advisories/GHSA-h4x7-gw46-3wm6