THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h4x7-gw46-3wm6 (medium) — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

[GHSA] GHSA-h4x7-gw46-3wm6 (medium) — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

medgithub_advisoriesPublished 2026-09-08

GHSA-h4x7-gw46-3wm6 Severity: medium CVE: CVE-2026-84379

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

### Summary

HTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence uploa

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h4x7-gw46-3wm6