Known vulnerabilities in Apache HttpComponents
Vendor:
Apache Foundation
Software:
Apache HttpComponents
Software CPE:
cpe:2.3:a:apache_foundation:apache_httpcomponents:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
5.5-beta1
5.6.4
5.6.3
5.6.2
5.6.1
5.6
5.5.2
5.5.1
5.3.6
5.3.5
5.5
5.4.4
5.4.3
5.3.4
5.4.2
5.3.3
5.3.2
5.4.1
5.4
5.2.5
5.3.1
5.3
5.2.4
5.2.3
5.2.2
5.2.1
4.5.14
4.4.16
5.1.5
5.2
5.1.4
5.1.3
4.4.15
5.1.2
5.1.1
5.0.4
5.1
4.4.14
5.0.3
4.5.13
5.0.2
4.5.12
4.5.11
4.5.10
4.5.9
4.5.8
4.5.7
4.5.6
4.5.5
4.5.4
4.5.3
4.5.2
4.5
4.3.6
4.3.5
4.3.4
4.2.6
4.0.3
4.0.2
5.0.1
5.0
4.4.13
4.4.12
4.4.11
4.4.10
4.4.9
4.4.8
4.4.7
4.4.6
4.4.5
4.4.4
4.4.3
4.4.2
4.4.1
4.4
4.3.3
4.3.2
4.3.1
4.3
4.2.5
4.2.4
4.2.3
4.2.2
4.2
4.1.4
4.1.3
4.1.2
4.1.1
4.1
4.0.1
4.0
4.5.1
4.2.1
3.1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145266 - Resource exhaustion CVE-2026-54399 |
CWE-400 | Medium | 5.5 | 25.08.2026 |
SB2026082579 SB2026090315 |
||
| #VU145265 - Allocation of Resources Without Limits or Throttling CVE-2026-54428 |
CWE-770 | Medium | 5.5 | 25.08.2026 |
SB2026082579 SB2026091639 |
||
| #VU47481 - Improper input validation CVE-2020-13956 |
CWE-20 | Medium | 4.5.13, 5.0.3 | 09.10.2020 |
SB2020100902 SB2020101604 SB2021042104 and 77 more |