Skip to content

[Related to 7123] CWE-770: Allocation of Resources Without Limits or Throttling through org.apache.httpcomponents.client5:httpclient5@5.6.1 #7131

Description

@maurogonzalez

Describe the bug

Attended here #7123 by @bhoradc but build failed

Image

CVE-2026-54428
CWE-770: Allocation of Resources Without Limits or Throttling

Snyk: CVSS v4.0 7.1 - High Severity

CVSS v3.1 6.5 - Medium Severity

software.amazon.awssdk:aws-sdk-java@2.46.21 › software.amazon.awssdk:sns-message-manager@2.46.21 › org.apache.httpcomponents.client5:httpclient5@5.6.1 › org.apache.httpcomponents.core5:httpcore5-h2@5.4

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Update org.apache.httpcomponents.client5:httpclient5 from 5.6.1 -> 5.6.2

Current Behavior

org.apache.httpcomponents.client5:httpclient5 from 5.6.1 https://www.cve.org/CVERecord?id=CVE-2026-54428

Reproduction Steps

https://www.cve.org/CVERecord?id=CVE-2026-54428

Possible Solution

Update org.apache.httpcomponents.client5:httpclient5 from 5.6.1 -> 5.6.2

Additional Information/Context

No response

AWS Java SDK version used

2.46.21,2.47.4

JDK version used

21

Operating System and version

Amazon Linux 2023 (AL2023)

Metadata

Metadata

Assignees

Labels

bugThis issue is a bug.p2This is a standard priority issue

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions