Junglewise Threat Intelligence

CVE-2026-90455: Reverted HTTP client library version reintroduces vulnerable dependency

CVE-2026-90455 · Severity: info · Published 2026-09-11

Technologies: <UNKNOWN>.

Executive brief

A log-processing component shipped with a vendor product was patched to include a fixed version of an HTTP client library, but that patch was later reverted, reintroducing the earlier vulnerable version. While the component only makes a single initialization request to a trusted vendor URL and does not process attacker input through the library, the presence of known vulnerabilities in a bundled dependency raises supply-chain risk and complicates future maintenance.

Technical details

A prior code update upgraded a bundled HTTP client library to a patched version that resolved known vulnerabilities, but was subsequently reverted, restoring an earlier vulnerable version of the library into the log-processing component. The vulnerable library is only invoked in a single code path during component initialization to fetch configuration or data from a fixed, hardcoded trusted vendor endpoint. Since the attacker-controlled input does not flow through the reintroduced HTTP client, direct exploitation of the library's known vulnerabilities in this context is limited. However, the presence of unpatched vulnerabilities in a bundled third-party component increases supply-chain risk and may become exploitable if the component's use of the library is refactored or expanded in future releases.

Affected products

  • <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References