Executive brief
A log-processing component shipped with a vendor product was patched to include a fixed version of an HTTP client library, but that patch was later reverted, reintroducing the earlier vulnerable version. While the component only makes a single initialization request to a trusted vendor URL and does not process attacker input through the library, the presence of known vulnerabilities in a bundled dependency raises supply-chain risk and complicates future maintenance.
Technical details
A prior code update upgraded a bundled HTTP client library to a patched version that resolved known vulnerabilities, but was subsequently reverted, restoring an earlier vulnerable version of the library into the log-processing component. The vulnerable library is only invoked in a single code path during component initialization to fetch configuration or data from a fixed, hardcoded trusted vendor endpoint. Since the attacker-controlled input does not flow through the reintroduced HTTP client, direct exploitation of the library's known vulnerabilities in this context is limited. However, the presence of unpatched vulnerabilities in a bundled third-party component increases supply-chain risk and may become exploitable if the component's use of the library is refactored or expanded in future releases.
Affected products
- <UNKNOWN>
Timeline
- 2026-09-11: disclosed