Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54428

Опубликовано: 01 июл. 2026
Источник: debian
EPSS Низкий

Описание

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
httpcomponents-core5unfixedpackage
httpcomponents-core5no-dsatrixiepackage
httpcomponents-core5postponedbookwormpackage
httpcomponents-coreunfixedpackage
httpcomponents-coreno-dsatrixiepackage
httpcomponents-corenot-affectedbookwormpackage
httpcomponents-corenot-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/07/01/3

  • v4 possibly not affected, needs further validation once fix is identified

EPSS

Процентиль: 45%
0.00587
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

CVSS3: 7.5
redhat
около 1 месяца назад

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

CVSS3: 7.5
nvd
около 1 месяца назад

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

CVSS3: 7.5
github
около 1 месяца назад

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

EPSS

Процентиль: 45%
0.00587
Низкий