Resource exhaustion in Apache HttpComponents - CVE-2026-54399
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the HTTP/1.1 message parser when processing messages with an excessive number of headers or excessive header length. A remote attacker can send a specially crafted HTTP message to cause a denial of service.
The issue leads to memory exhaustion.
Affected software
IBM Common Licensing
How to mitigate CVE-2026-54399
IBM Common Licensing - update to 9.1