GHSA-hf6x-8p5f-cgmf

Suggest an improvement
Source
https://github.com/advisories/GHSA-hf6x-8p5f-cgmf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hf6x-8p5f-cgmf/GHSA-hf6x-8p5f-cgmf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-hf6x-8p5f-cgmf
Aliases
Downstream
Published
2026-07-01T18:31:55Z
Modified
2026-08-12T19:41:11Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
Details

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows a remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-12T19:24:45Z",
    "nvd_published_at":  "2026-07-01T17:16:36Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.apache.httpcomponents.core5:httpcore5

Package

Name
org.apache.httpcomponents.core5:httpcore5
View open source insights on deps.dev
Purl
pkg:maven/org.apache.httpcomponents.core5/httpcore5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.4.3

Affected versions

5.*
5.0-alpha1
5.0-alpha2
5.0-alpha3
5.0-alpha4
5.0-beta1
5.0-beta2
5.0-beta3
5.0-beta4
5.0-beta5
5.0-beta6
5.0-beta7
5.0-beta8
5.0-beta9
5.0-beta10
5.0-beta11
5.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1-beta1
5.1-beta2
5.1-beta3
5.1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2-alpha1
5.2-alpha2
5.2-beta1
5.2-beta2
5.2
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.3-alpha1
5.3-alpha2
5.3-beta1
5.3
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.4-alpha1
5.4
5.4.1
5.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hf6x-8p5f-cgmf/GHSA-hf6x-8p5f-cgmf.json"

Maven / org.apache.httpcomponents.core5:httpcore5

Package

Name
org.apache.httpcomponents.core5:httpcore5
View open source insights on deps.dev
Purl
pkg:maven/org.apache.httpcomponents.core5/httpcore5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5-alpha1
Fixed
5.5-beta2

Affected versions

5.*
5.5-alpha1
5.5-beta1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hf6x-8p5f-cgmf/GHSA-hf6x-8p5f-cgmf.json"