CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-41945

Critical · CVSS 9.1

Encode OSS httpx (PyPI:httpx) — Improper Input Validation (CWE-20) in URL parsing

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-20

Description

Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

Search profile — drives PoC discovery

Symbols httpx.URLhttpx.Clienthttpx.URL.copy_withcopy_withhttpx._urlsURL.__init__httpx._client
Keywords CVE-2021-41945httpx improper input validationhttpx URL validation bypasshttpx copy_with exploithttpx SSRFhttpx URL parsing vulnerabilityencode httpx PoChttpx < 0.23.0 vulnerabilitylebr0nli httpx
Versions: < 0.23.0

Affected packages

PyPI httpx 0 → 0.20.0
PyPI httpx 0 → 0.23.0

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z