VAITP Dataset

← Back to the dataset

CVE-2026-84381

TLS not enforced for wss over SOCKS5 proxy, exposing WebSocket data in plaintext.

  • CVSS 8.1
  • 319
  • Information Leakage
  • Remote

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.

CWE
319
CVSS base score
8.1
Published
2026-09-02
OWASP
A02 Cryptographic Failures
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Information Leakage
Subcategory
Information Disclosure
Accessibility scope
Remote
Impact
Information Disclosure
Affected component
httpcore2
Fixed by upgrading
Yes

Solution

Upgrade to httpcore2 ≥ 2.10.0 and httpx ≥ 2.10.0.

Vulnerable code sample

import httpcore2
from httpcore2._sync.socks_proxy import SOCKSProxy

def open_connection(origin_scheme: str, proxy: SOCKSProxy):
    """
    Establish a connection through a SOCKS5 proxy.
    """
    conn = proxy.connect()
    # VULNERABLE: TLS upgrade only for https, not wss
    if origin_scheme == "https":
        conn.start_tls(verify=True)
    return conn

Patched code sample

import httpcore2
from httpcore2._sync.socks_proxy import SOCKSProxy

def open_connection(origin_scheme: str, proxy: SOCKSProxy):
    """
    Establish a connection through a SOCKS5 proxy.
    """
    conn = proxy.connect()
    # FIX: TLS upgrade for both https and wss schemes
    if origin_scheme in ("https", "wss"):
        conn.start_tls(verify=True)
    return conn

Cite this entry

@misc{vaitp:cve202684381,
  title        = {{TLS not enforced for wss over SOCKS5 proxy, exposing WebSocket data in plaintext.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-84381},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-84381/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::