Allocation of Resources Without Limits or Throttling in Apache HttpComponents - CVE-2026-54428
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the HTTP/2 HPACK decoder when processing compressed header blocks before the HTTP/2 SETTINGS acknowledgement. A remote attacker can send oversized compressed header blocks to cause a denial of service.
The issue can lead to memory exhaustion before the configured header list size limit is applied.
Affected software
Crucible Data Center
Crucible Server
How to mitigate CVE-2026-54428
Crucible Data Center - update to 4.9.14
Crucible Server - update to 4.9.14