CVE-2026-84378 | Pydantic Httpx2 up to 2.9.x Server-Sent Events Parser _sse.py _SSELineDecoder.decode information exposure through microarchitectural state after transient execution
A vulnerability, which was classified as problematic, has been found in Pydantic Httpx2 up to 2.9.x. The impacted element is the function _SSELineDecoder.decode of the file src/httpx2/httpx2/_sse.py of the component Server-Sent Events Parser. The manipulation leads to information exposure through microarchitectural state after transient execution.
This vulnerability is listed as CVE-2026-84378. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More