Apache · Httpcomponents Core · CVE-2026-54428
**Name of the Vulnerable Software and Affected Versions**
Apache HttpComponents Core versions prior to 5.4.3
Apache HttpComponents Core versions prior to 5.5-beta2
**Description**
An issue exists in the HTTP/2 HPACK decoder where resources are allocated without limits or throttling. A remote attacker can cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement triggers the application of the configured header list size limit.
**Recommendations**
Update Apache HttpComponents Core to version 5.4.3 or later.
Update Apache HttpComponents Core to version 5.5-beta2 or later.