CVE-2026-84381
TLS not enforced for wss over SOCKS5 proxy, exposing WebSocket data in plaintext.
- CVSS 8.1
- 319
- Information Leakage
- Remote
HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.
- CWE
- 319
- CVSS base score
- 8.1
- Published
- 2026-09-02
- OWASP
- A02 Cryptographic Failures
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Information Leakage
- Subcategory
- Information Disclosure
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Affected component
- httpcore2
- Fixed by upgrading
- Yes
Solution
Upgrade to httpcore2 ≥ 2.10.0 and httpx ≥ 2.10.0.
Vulnerable code sample
import httpcore2
from httpcore2._sync.socks_proxy import SOCKSProxy
def open_connection(origin_scheme: str, proxy: SOCKSProxy):
"""
Establish a connection through a SOCKS5 proxy.
"""
conn = proxy.connect()
# VULNERABLE: TLS upgrade only for https, not wss
if origin_scheme == "https":
conn.start_tls(verify=True)
return connPatched code sample
import httpcore2
from httpcore2._sync.socks_proxy import SOCKSProxy
def open_connection(origin_scheme: str, proxy: SOCKSProxy):
"""
Establish a connection through a SOCKS5 proxy.
"""
conn = proxy.connect()
# FIX: TLS upgrade for both https and wss schemes
if origin_scheme in ("https", "wss"):
conn.start_tls(verify=True)
return connCite this entry
@misc{vaitp:cve202684381,
title = {{TLS not enforced for wss over SOCKS5 proxy, exposing WebSocket data in plaintext.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-84381},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-84381/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
