© 2025-2026 PySpect
First version without a known vulnerability: 2.12.0
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
Fixed in: 2.12.0
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
Fixed in: 2.11.0
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
Fixed in: 2.11.0
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
Fixed in: 2.10.0
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
Fixed in: 2.10.0