CVE-2026-54428
ADVISORY - githubSummary
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Common Weakness Enumeration (CWE)
Uncontrolled Resource Consumption
GitHub
3.9
CVSS SCORE
7.5highDebian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-29v8-qq52-35w6
-
minimos
MINI-2xqp-2p4c-j3mm
-
minimos
MINI-45w5-7vp8-cfpc
-
minimos
MINI-4f6f-43rp-59wq
-
minimos
MINI-54m9-px5v-56rj
-
minimos
MINI-67cc-m87r-h763
-
minimos
MINI-79rj-vmq9-6hqf
-
minimos
MINI-f489-rj7v-hwrr
-
minimos
MINI-f4hx-5659-w9w9
-
minimos
MINI-g25r-7x83-4qq3
-
minimos
MINI-jhh8-9g49-xhq5
-
minimos
MINI-jw7c-3p2h-j746
-
minimos
MINI-m53p-r8m9-3x2q
-
minimos
MINI-p66p-gq99-24cg
-
minimos
MINI-p7jj-37fc-2373
-
minimos
MINI-qfqp-xjf4-284q
-
minimos
MINI-qhcr-4jjc-4gr3
-
minimos
MINI-qw3q-3rhg-4jgm
-
minimos
MINI-vfqj-m944-hgxr
-
minimos
MINI-wr6r-8jvh-43w4
-