Search CVE reports


Toggle filters

1 – 3 of 3 results


CVE-2026-71290

Medium priority
Needs evaluation

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept...

1 affected package

httpcomponents-core5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
httpcomponents-core5 Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-54428

Medium priority
Needs evaluation

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory...

2 affected packages

httpcomponents-core, httpcomponents-core5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
httpcomponents-core Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
httpcomponents-core5 Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-54399

Medium priority
Needs evaluation

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory...

2 affected packages

httpcomponents-core, httpcomponents-core5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
httpcomponents-core Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
httpcomponents-core5 Needs evaluation Needs evaluation Needs evaluation — —
Show less packages