HTTPie is a command-line HTTP client built for human interaction with APIs and web services, with its vulnerability footprint centered on the single HTTPie product. The recurring weakness classes involve sensitive-information exposure, certificate validation gaps, and open-redirect risks, reflecting the security-relevant responsibilities of an HTTP client handling credentials, TLS negotiation, and URL navigation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Httpie over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10751HIGH All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to t | Aug 23, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-24737MEDIUM HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests a | Mar 7, 2022 | 6.5 | 23 | NO | NO |
CVE-2023-48052HIGH Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack. | Nov 16, 2023 | 7.4 | 19 | NO | NO |
CVE-2022-0430MEDIUM Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0. | Mar 15, 2022 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Httpie.
Media articles that mention a CVE ID that affects a product developed by Httpie — matched by CVE ID, not by vendor name.