CVE-2026-54428: Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HttpComponents Coreto a version that resolves this vulnerability.Fixed in 5.4.2 and earlier - Upgrade
Upgrade
Apache HttpComponents Coreto a version that resolves this vulnerability.Fixed in 5.5-beta1 and earlier - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-54428
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54428?
CVE-2026-54428 has a high severity rating of 7.5 according to the CVSS 3.1 score.
How do I fix CVE-2026-54428?
To address CVE-2026-54428, upgrade to Apache HttpComponents Core version 5.4.3 or later.
What does CVE-2026-54428 affect?
CVE-2026-54428 affects Apache HttpComponents Core versions 5.4.2 and earlier, as well as 5.5-beta1 and earlier.
What type of attack is associated with CVE-2026-54428?
CVE-2026-54428 allows remote attackers to perform a denial of service attack through memory exhaustion.
What component of Apache is vulnerable in CVE-2026-54428?
The vulnerability in CVE-2026-54428 exists in the HTTP/2 HPACK decoder of Apache HttpComponents Core.