CVE-2021-41945: Input Validation
Encode OSS httpx < 0.23.0 is affected by improper input validation in httpx.URL, httpx.Client and some functions using httpx.URL.copywith.
Other sources
Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in httpx.URL, httpx.Client and some functions using httpx.URL.copywith.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41945?
CVE-2021-41945 is a vulnerability affecting Encode OSS httpx version 0.23.0 and below, where improper input validation in `httpx.URL`, `httpx.Client`, and some functions using `httpx.URL.copy_with` can lead to security issues.
How severe is CVE-2021-41945?
CVE-2021-41945 has a severity rating of 9.1 (Critical).
Which software versions are affected by CVE-2021-41945?
The affected software versions include Encode OSS httpx version 0.23.0 and below, as well as Encode Httpx version up to exclusive 0.23.0.
How can I fix the CVE-2021-41945 vulnerability?
To fix the CVE-2021-41945 vulnerability, update the httpx package to version 0.23.0 or higher.
Where can I find more information about CVE-2021-41945?
You can find more information about CVE-2021-41945 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-41945), [GitHub Issue](https://github.com/encode/httpx/issues/2184), [Gist](https://gist.github.com/lebr0nli/4edb76bbd3b5ff993cf44f2fbce5e571).