HIGHMaven

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

CVE-2026-54399Published 1 month agoUpdated 1 week agoSource: OSV

Affected packages

  • org.apache.httpcomponents.core5:httpcore5before 5.4.3

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service | HackTribune