{"id":"GHSA-hf6x-8p5f-cgmf","summary":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service","details":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows a remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length","aliases":["CVE-2026-54399"],"modified":"2026-09-10T03:50:52.486045504Z","published":"2026-07-01T18:31:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-12T19:24:45Z","nvd_published_at":"2026-07-01T17:16:36Z","cwe_ids":["CWE-400"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399"},{"type":"WEB","url":"https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"},{"type":"WEB","url":"https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"},{"type":"PACKAGE","url":"https://github.com/apache/httpcomponents-core"},{"type":"WEB","url":"https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/01/4"}],"affected":[{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","ecosystem":"Maven","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.3"}]}],"versions":["5.0","5.0-alpha1","5.0-alpha2","5.0-alpha3","5.0-alpha4","5.0-beta1","5.0-beta10","5.0-beta11","5.0-beta2","5.0-beta3","5.0-beta4","5.0-beta5","5.0-beta6","5.0-beta7","5.0-beta8","5.0-beta9","5.0.1","5.0.2","5.0.3","5.0.4","5.1","5.1-beta1","5.1-beta2","5.1-beta3","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.2","5.2-alpha1","5.2-alpha2","5.2-beta1","5.2-beta2","5.2.1","5.2.2","5.2.3","5.2.4","5.2.5","5.3","5.3-alpha1","5.3-alpha2","5.3-beta1","5.3.1","5.3.2","5.3.3","5.3.4","5.3.5","5.3.6","5.4","5.4-alpha1","5.4.1","5.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hf6x-8p5f-cgmf/GHSA-hf6x-8p5f-cgmf.json"}},{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","ecosystem":"Maven","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.5-alpha1"},{"fixed":"5.5-beta2"}]}],"versions":["5.5-alpha1","5.5-beta1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hf6x-8p5f-cgmf/GHSA-hf6x-8p5f-cgmf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}