Junglewise Threat Intelligence

CVE-2026-54399: Apache HttpComponents Core uncontrolled resource consumption in HTTP/1.1 parser

CVE-2026-54399 · Severity: high · CVSS 7.5 · Published 2026-07-01

Vendors: Apache, Apache Software Foundation.

Executive brief

Apache HttpComponents Core, a foundational library used by many Java applications to handle web communications, is vulnerable to a denial-of-service attack. An attacker can send specially crafted web requests with an excessive number of headers or extremely long headers to exhaust the server's memory. This can cause the affected application to crash or become unresponsive, disrupting business operations and service availability.

Technical details

An uncontrolled resource consumption vulnerability exists in the HTTP/1.1 message parser of Apache HttpComponents Core. The root cause is insufficient validation of the number of headers and the length of individual headers within incoming HTTP/1.1 messages. A remote, unauthenticated attacker can exploit this by sending a stream of malicious requests designed to consume all available heap memory, leading to a Denial of Service (DoS) via memory exhaustion. The vulnerability is addressed in versions 5.4.3 and 5.5-beta2.

Affected products

  • Apache HttpComponents Core <= 5.4.2, 5.5-alpha1 to 5.5-beta1

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory
  • 2026-07-01: patched: Fixed in 5.4.3 and 5.5-beta2

References

Related threats