Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
References
Link Resource
http://encode.com Vendor Advisory
https://gist.github.com/lebr0nli/4edb76bbd3b5ff993cf44f2fbce5e571 Exploit Third Party Advisory
https://github.com/encode/httpx Product Third Party Advisory
https://github.com/encode/httpx/discussions/1831 Exploit Issue Tracking Third Party Advisory
https://github.com/encode/httpx/issues/2184 Exploit Issue Tracking Third Party Advisory
https://github.com/encode/httpx/releases/tag/0.23.0 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-04-28T13:22:10

Updated: 2022-05-23T17:08:42

Reserved: 2021-10-04T00:00:00


Link: CVE-2021-41945

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-04-28T14:15:07.617

Modified: 2022-10-12T02:40:46.830


Link: CVE-2021-41945

JSON object: View

cve-icon Redhat Information

No data.

CWE