THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7mj9-2mp8-4m2p (high) — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

[GHSA] GHSA-7mj9-2mp8-4m2p (high) — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

highgithub_advisoriesPublished 2026-09-08

GHSA-7mj9-2mp8-4m2p Severity: high CVE: CVE-2026-84381

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

### Summary

httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.

The transport

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7mj9-2mp8-4m2p