<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:34:44 +0000</lastBuildDate>
    <item>
      <title>BREW-bump-my-version-CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies</title>
      <link>https://cve.radiocsirt.org/vuln/brew-bump-my-version-cve-2026-84381</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bump-my-version&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.&lt;/p&gt;
&lt;p&gt;The transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.&lt;/p&gt;
&lt;p&gt;For example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:&lt;/p&gt;
&lt;p&gt;```python
import httpx2&lt;/p&gt;
&lt;p&gt;with httpx2.Client(proxy=&amp;#34;socks5://proxy.example:1080&amp;#34;) as client:
    with client.websocket(
        &amp;#34;wss://service.example/private?token=query-secret&amp;#34;,
        headers={&amp;#34;Authorization&amp;#34;: &amp;#34;Bearer header-secret&amp;#34;},
        cookies={&amp;#34;session&amp;#34;: &amp;#34;cookie-secret&amp;#34;},
    ) as websocket:
        websocket.send_text(&amp;#34;private message&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;On affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:&lt;/p&gt;
&lt;p&gt;```t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bump-my-version&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.&lt;/p&gt;
&lt;p&gt;The transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.&lt;/p&gt;
&lt;p&gt;For example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:&lt;/p&gt;
&lt;p&gt;```python
import httpx2&lt;/p&gt;
&lt;p&gt;with httpx2.Client(proxy=&amp;#34;socks5://proxy.example:1080&amp;#34;) as client:
    with client.websocket(
        &amp;#34;wss://service.example/private?token=query-secret&amp;#34;,
        headers={&amp;#34;Authorization&amp;#34;: &amp;#34;Bearer header-secret&amp;#34;},
        cookies={&amp;#34;session&amp;#34;: &amp;#34;cookie-secret&amp;#34;},
    ) as websocket:
        websocket.send_text(&amp;#34;private message&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;On affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:&lt;/p&gt;
&lt;p&gt;```t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-bump-my-version-cve-2026-84381</guid>
    </item>
    <item>
      <title>CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-84381</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic httpx2, pydantic httpcore2&lt;/p&gt;
&lt;p&gt;HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic httpx2, pydantic httpcore2&lt;/p&gt;
&lt;p&gt;HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-84381</guid>
    </item>
    <item>
      <title>GHSA-7mj9-2mp8-4m2p — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7mj9-2mp8-4m2p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: httpcore2, PyPI: httpx2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.&lt;/p&gt;
&lt;p&gt;The transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.&lt;/p&gt;
&lt;p&gt;For example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:&lt;/p&gt;
&lt;p&gt;```python
import httpx2&lt;/p&gt;
&lt;p&gt;with httpx2.Client(proxy=&amp;#34;socks5://proxy.example:1080&amp;#34;) as client:
    with client.websocket(
        &amp;#34;wss://service.example/private?token=query-secret&amp;#34;,
        headers={&amp;#34;Authorization&amp;#34;: &amp;#34;Bearer header-secret&amp;#34;},
        cookies={&amp;#34;session&amp;#34;: &amp;#34;cookie-secret&amp;#34;},
    ) as websocket:
        websocket.send_text(&amp;#34;private message&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;On affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:&lt;/p&gt;
&lt;p&gt;```t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: httpcore2, PyPI: httpx2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.&lt;/p&gt;
&lt;p&gt;The transport flaw affects httpcore2 releases before `2.10.0`. HTTPX2 exposed this behavior through its public `Client.websocket()` and `AsyncClient.websocket()` APIs from `2.6.0` through `2.9.1`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The synchronous and asynchronous SOCKS5 connection implementations upgrade the established proxy tunnel to TLS only when the remote origin scheme is `https`. The equivalent check does not include `wss`. After the SOCKS5 handshake succeeds, the raw stream is therefore passed directly to the HTTP/1.1 connection, which writes the WebSocket upgrade request without first performing a TLS handshake or verifying the destination certificate.&lt;/p&gt;
&lt;p&gt;For example, an application using HTTPX2 `2.6.0` through `2.9.1` may open an authenticated WebSocket through a SOCKS proxy:&lt;/p&gt;
&lt;p&gt;```python
import httpx2&lt;/p&gt;
&lt;p&gt;with httpx2.Client(proxy=&amp;#34;socks5://proxy.example:1080&amp;#34;) as client:
    with client.websocket(
        &amp;#34;wss://service.example/private?token=query-secret&amp;#34;,
        headers={&amp;#34;Authorization&amp;#34;: &amp;#34;Bearer header-secret&amp;#34;},
        cookies={&amp;#34;session&amp;#34;: &amp;#34;cookie-secret&amp;#34;},
    ) as websocket:
        websocket.send_text(&amp;#34;private message&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;On affected versions, the stream passing through the SOCKS proxy begins with a plaintext request such as:&lt;/p&gt;
&lt;p&gt;```t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7mj9-2mp8-4m2p</guid>
    </item>
  </channel>
</rss>
