[Git][security-tracker-team/security-tracker][master] Track fixed version for httpcomponents-core5 issues via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 8 08:00:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
31bd1d5a by Salvatore Bonaccorso at 2026-08-08T08:59:56+02:00
Track fixed version for httpcomponents-core5 issues via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -30963,7 +30963,7 @@ CVE-2026-55510 (ImageMagick is free and open-source software used for editing an
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/fba7768a5fe69b795a87e3f2f65b0225a4bcc38e (6.9.13-51)
 	NOTE: Introduced with: https://github.com/ImageMagick/ImageMagick6/commit/998cdc0387cef25d38709984bdde0125b83f867a (6.9.13-42)
 CVE-2026-54428 (Allocation of resources without limits or throttling in the HTTP/2 HPA ...)
-	- httpcomponents-core5 <unfixed> (bug #1141387)
+	- httpcomponents-core5 5.4.3-1 (bug #1141387)
 	[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
 	[bookworm] - httpcomponents-core5 <postponed> (Minor issue; HTTP/2 HPACK decoder present in 5.x, unlike 4.x)
 	- httpcomponents-core <unfixed>
@@ -30973,7 +30973,7 @@ CVE-2026-54428 (Allocation of resources without limits or throttling in the HTTP
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/01/3
 	NOTE: v4 possibly not affected, needs further validation once fix is identified
 CVE-2026-54399 (Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 messag ...)
-	- httpcomponents-core5 <unfixed> (bug #1141387)
+	- httpcomponents-core5 5.4.3-1 (bug #1141387)
 	[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
 	[bookworm] - httpcomponents-core5 <postponed> (Minor issue)
 	- httpcomponents-core <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31bd1d5abcf44b85d95deebff6bcaff6d0bab7da

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31bd1d5abcf44b85d95deebff6bcaff6d0bab7da
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/e26219b2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list