Skip to content

[Related to 7123] CWE-770: Allocation of Resources Without Limits or Throttling through org.apache.httpcomponents.client5:httpclient5@5.6.1 #7131

Description

@maurogonzalez

Describe the bug

Attended here #7123 by @bhoradc but build failed

Image

CVE-2026-54428
CWE-770: Allocation of Resources Without Limits or Throttling

Snyk: CVSS v4.0 7.1 - High Severity

CVSS v3.1 6.5 - Medium Severity

software.amazon.awssdk:aws-sdk-java@2.46.21 › software.amazon.awssdk:sns-message-manager@2.46.21 › org.apache.httpcomponents.client5:httpclient5@5.6.1 › org.apache.httpcomponents.core5:httpcore5-h2@5.4

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Update org.apache.httpcomponents.client5:httpclient5 from 5.6.1 -> 5.6.2

Current Behavior

org.apache.httpcomponents.client5:httpclient5 from 5.6.1 https://www.cve.org/CVERecord?id=CVE-2026-54428

Reproduction Steps

https://www.cve.org/CVERecord?id=CVE-2026-54428

Possible Solution

Update org.apache.httpcomponents.client5:httpclient5 from 5.6.1 -> 5.6.2

Additional Information/Context

No response

AWS Java SDK version used

2.46.21,2.47.4

JDK version used

21

Operating System and version

Amazon Linux 2023 (AL2023)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugThis issue is a bug.p2This is a standard priority issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions