MEDIUM SEVERITYCONFIRMED

unquote("") raises IndexError on empty string

Package
httpx
Version
0.28.1
Verified
2026-03-28

Description

The httpx `unquote()` utility evaluates `value[0] == value[-1] == '"'` before checking string length. An empty string causes `IndexError: string index out of range` because Python does not short-circuit before the index access.

Reproduction

from httpx._utils import unquote
unquote("")
# IndexError: string index out of range
← All bugsScan your code →