Httplib2 is a lightweight HTTP client library for Python that, despite a narrow product scope, sees broad distribution as a dependency across Python applications and services. The recurring vulnerability pattern centers on request-handling and input-validation issues, including CRLF injection, improper neutralization of special elements, and resource-consumption flaws that reflect the parsing demands inherent to HTTP protocol implementation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Httplib2 Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59939HIGH httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip o | Jul 8, 2026 | 7.5 | 34 | NO | NO |
CVE-2021-21240HIGH httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-a | Feb 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-11078MEDIUM In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden request | May 20, 2020 | 6.8 | 19 | NO | NO |
httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl | Jan 18, 2014 | 2.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Httplib2 Project.
Media articles that mention a CVE ID that affects a product developed by Httplib2 Project — matched by CVE ID, not by vendor name.