{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/httpx2-2.6.0-2.9.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-84381"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["httpcore2 (\u003c 2.10.0)","httpx2 (2.6.0-2.9.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","transport-security","proxy"],"_cs_type":"advisory","_cs_vendors":["encode"],"content_html":"\u003cp\u003eThe Python libraries httpcore2 (releases prior to 2.10.0) and httpx2 (releases 2.6.0 through 2.9.1) contain a security vulnerability where TLS is not correctly initialized for secure WebSocket (\u003ccode\u003ewss://\u003c/code\u003e) connections routed through SOCKS5 proxies. The SOCKS5 connection implementation includes a check to upgrade to TLS only for \u003ccode\u003ehttps\u003c/code\u003e origins, failing to include \u003ccode\u003ewss\u003c/code\u003e in the logic. Consequently, the client transmits the WebSocket opening handshake and all subsequent frames in plaintext through the proxy. This vulnerability, tracked as CVE-2026-84381, violates RFC 6455 requirements for secure WebSocket communication, rendering the transport susceptible to interception, modification, and server impersonation by any actor controlling or observing the SOCKS proxy path.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a malicious or compromised SOCKS proxy to intercept sensitive information, including URL query parameters, authentication tokens in Authorization headers, and session cookies. Furthermore, because the TLS handshake is bypassed, the client fails to verify the server's certificate, enabling an attacker to perform man-in-the-middle attacks by impersonating the target server and injecting or altering application-level WebSocket messages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of \u003ccode\u003ehttpx2\u003c/code\u003e and \u003ccode\u003ehttpcore2\u003c/code\u003e to version \u003ccode\u003e2.10.0\u003c/code\u003e or later.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, modify application configuration to bypass SOCKS proxies for all \u003ccode\u003ewss://\u003c/code\u003e connections.\u003c/li\u003e\n\u003cli\u003eReview application logs for WebSocket traffic originating from servers configured to use SOCKS5 proxies to identify potential exposure.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-84381 across all environments utilizing affected versions of the HTTPX2 library.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T21:53:21Z","date_published":"2026-09-08T21:53:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-httpx2-socks-tls/","summary":"A transport flaw in httpcore2 and httpx2 fails to establish TLS for wss:// connections routed through SOCKS5 proxies, exposing authentication headers, cookies, and message payloads in plaintext to proxy intermediaries.","title":"Plaintext WebSocket Exposure in HTTPX2 and httpcore2 via SOCKS5 Proxy","url":"https://feed.craftedsignal.io/briefs/2026-09-httpx2-socks-tls/"}],"language":"en","title":"CraftedSignal Threat Feed - Httpx2 (2.6.0-2.9.1)","version":"https://jsonfeed.org/version/1.1"}