Skip to content

[馃惛 Frogbot] Update version of org.apache.httpcomponents.core5:httpcore5 to 5.4.3 - #11

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
frogbot-org.apache.httpcomponents.core5_httpcore5-e8e1328a580b4a03a83199881787637b
Open

[馃惛 Frogbot] Update version of org.apache.httpcomponents.core5:httpcore5 to 5.4.3#11
github-actions[bot] wants to merge 1 commit into
masterfrom
frogbot-org.apache.httpcomponents.core5_httpcore5-e8e1328a580b4a03a83199881787637b

Conversation

@github-actions

Copy link
Copy Markdown

馃毃 This automated pull request was created by Frogbot and fixes the below:

馃摝 Vulnerable Dependencies

Severity ID Contextual Analysis Direct Dependencies Impacted Dependency Fixed Versions
high (not applicable)
High
CVE-2026-54399 Not Applicable org.apache.httpcomponents.core5:httpcore5:5.3.4 org.apache.httpcomponents.core5:httpcore5 5.3.4 [5.5-beta2]
[5.4.3]

馃敄 Details

Vulnerability Details

Contextual Analysis: Not Applicable
Direct Dependencies: org.apache.httpcomponents.core5:httpcore5:5.3.4
Impacted Dependency: org.apache.httpcomponents.core5:httpcore5:5.3.4
Fixed Versions: [5.5-beta2], [5.4.3]
CVSS V3: 7.5

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser聽in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows聽an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant