Multiple vulnerabilities in Apache HttpComponents Core enable a remote, anonymous attacker to conduct a Denial of Service attack, with a CVSS Base Score of 7.5 (High). Affected versions are Apache HttpComponents Core prior to version 5.4.3 and prior to the 5.5-beta2 release. The advisory recommends applying the available mitigations.
[WID-SEC-2026-2172] Apache HttpComponents Core: Mehrere Schwachstellen ermöglichen Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 01.07.2026 Stand 02.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Apache HttpComponents ist ein Toolset von HTTP Java Komponenten. Produkte 01.07.2026 Apache HttpComponents <5.4.3 Apache HttpComponents <5.5-beta2 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HttpComponents Core ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben