CVE-2021-41945
Critical · CVSS 9.1Encode OSS httpx (PyPI:httpx) — Improper Input Validation (CWE-20) in URL parsing
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-20
Description
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
Search profile — drives PoC discovery
Symbols httpx.URLhttpx.Clienthttpx.URL.copy_withcopy_withhttpx._urlsURL.__init__httpx._client
Keywords CVE-2021-41945httpx improper input validationhttpx URL validation bypasshttpx copy_with exploithttpx SSRFhttpx URL parsing vulnerabilityencode httpx PoChttpx < 0.23.0 vulnerabilitylebr0nli httpx
Versions: < 0.23.0
Affected packages
| PyPI | httpx | 0 → 0.20.0 |
| PyPI | httpx | 0 → 0.23.0 |
References
- https://gist.github.com/lebr0nli/4edb76bbd3b5ff993cf44f2fbce5e571
- https://github.com/encode/httpx
- https://github.com/encode/httpx/discussions/1831
- https://github.com/encode/httpx/issues/2184
- https://github.com/encode/httpx/releases/tag/0.23.0
- http://encode.com
- https://gist.github.com/lebr0nli/4edb76bbd3b5ff993cf44f2fbce5e571
- https://github.com/encode/httpx
- https://github.com/encode/httpx/discussions/1831
- https://github.com/encode/httpx/issues/2184
- https://github.com/encode/httpx/releases/tag/0.23.0
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z