PT-2022-5665 · Encode Oss+2 · Httpx+2

·

CVE-2021-41945

·

Published

2022-04-28

·

Updated

2025-01-18

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Encode OSS httpx versions < 0.23.0 Encode OSS httpx version <=1.0.0.beta0
Description The issue is related to insufficient input validation in the httpx.URL and httpx.Client components, as well as in some functions that utilize httpx.URL.copy with. This could potentially allow a remote attacker to bypass existing security restrictions.
Recommendations For Encode OSS httpx versions < 0.23.0, update to version 0.23.0 or later to resolve the issue. For Encode OSS httpx version <=1.0.0.beta0, update to a version later than 1.0.0.beta0 to resolve the issue. As a temporary workaround, consider restricting the use of httpx.URL and httpx.Client until a patch is available. Avoid using functions that utilize httpx.URL.copy with in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2246
ALT-PU-2023-5210
BDU:2022-07059
CVE-2021-41945
GHSA-H8PJ-CXX2-JFG2
OPENSUSE-SU-2024:12041-1
OPENSUSE-SU-2025:14664-1
PYSEC-2022-183

Affected Products

Alt Linux
Debian
Httpx