CVE-2026-54428: Apache Httpcomponents Core

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

Affected products

  • Apache Httpcomponents Core: from 5.0, up to and including 5.4.2; version 5.5 only

Published 2026-07-01. Last modified 2026-07-24.