Allocation of Resources Without Limits or Throttling in Apache HttpComponents - CVE-2026-54428

 

Allocation of Resources Without Limits or Throttling in Apache HttpComponents - CVE-2026-54428

Published: August 25, 2026


Vulnerability identifier: #VU145265
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54428
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the HTTP/2 HPACK decoder when processing compressed header blocks before the HTTP/2 SETTINGS acknowledgement. A remote attacker can send oversized compressed header blocks to cause a denial of service.

The issue can lead to memory exhaustion before the configured header list size limit is applied.


Affected software

Apache HttpComponents
Crucible Data Center
Crucible Server

How to mitigate CVE-2026-54428

Install security update from vendor's website.

Apache HttpComponents - update to 5.5
Crucible Data Center - update to 4.9.14
Crucible Server - update to 4.9.14

External References

Related Security Bulletins