Debian Package Tracker
Register | Log in
Subscribe

httpcomponents-core5

set of low level HTTP transport components for Java

Choose email to subscribe with

general
  • source: httpcomponents-core5 (main)
  • version: 5.4.3-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Markus Koschany [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 5.2.1-1
  • stable: 5.2.2-1
  • testing: 5.4.2-1.1
  • unstable: 5.4.3-1
versioned links
  • 5.2.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.2.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.2-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libhttpcore5-java
action needed
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-54399: Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
  • CVE-2026-54428: Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Created: 2026-07-02 Last update: 2026-08-08 11:30
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-54399: (needs triaging) Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
  • CVE-2026-54428: (needs triaging) Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-02 Last update: 2026-08-08 11:30
testing migrations
  • excuses:
    • Migration status for httpcomponents-core5 (5.4.2-1.1 to 5.4.3-1): Will attempt migration (Any information below is purely informational)
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/h/httpcomponents-core5.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
news
[rss feed]
  • [2026-08-08] Accepted httpcomponents-core5 5.4.3-1 (source) into unstable (Jérôme Charaoui)
  • [2026-07-30] Accepted httpcomponents-core5 5.4.2-2 (source) into unstable (Jérôme Charaoui)
  • [2026-06-20] httpcomponents-core5 5.4.2-1.1 MIGRATED to testing (Debian testing watch)
  • [2026-06-15] Accepted httpcomponents-core5 5.4.2-1.1 (source) into unstable (Adrian Bunk)
  • [2026-03-17] Accepted httpcomponents-core5 5.4.2-1 (source) into unstable (Emmanuel Bourg)
  • [2026-02-15] httpcomponents-core5 5.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-09] Accepted httpcomponents-core5 5.4-1 (source) into unstable (Emmanuel Bourg)
  • [2025-11-03] httpcomponents-core5 5.2.2-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-29] Accepted httpcomponents-core5 5.2.2-2 (source) into unstable (Andrius Merkys)
  • [2023-09-16] httpcomponents-core5 5.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-11] Accepted httpcomponents-core5 5.2.2-1 (source) into unstable (Markus Koschany)
  • [2023-05-28] Accepted httpcomponents-core5 5.2.1-1~bpo11+1 (source) into bullseye-backports (Markus Koschany)
  • [2023-01-29] httpcomponents-core5 5.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-23] Accepted httpcomponents-core5 5.2.1-1 (source) into unstable (Markus Koschany)
  • [2022-11-19] httpcomponents-core5 5.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-13] Accepted httpcomponents-core5 5.2-1 (source) into unstable (Markus Koschany)
  • [2022-08-11] httpcomponents-core5 5.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-06] Accepted httpcomponents-core5 5.1.4-1 (source) into unstable (Markus Koschany)
  • [2022-01-06] Accepted httpcomponents-core5 5.1.3-1~bpo11+1 (source all) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-30] httpcomponents-core5 5.1.3-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-25] Accepted httpcomponents-core5 5.1.3-1 (source) into unstable (Markus Koschany)
  • [2021-12-24] Accepted httpcomponents-core5 5.1.2-2 (source) into unstable (Markus Koschany)
  • [2021-10-24] httpcomponents-core5 5.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-18] Accepted httpcomponents-core5 5.1.2-1 (source) into unstable (Markus Koschany)
  • [2021-08-26] httpcomponents-core5 5.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2021-08-20] Accepted httpcomponents-core5 5.0.3-2 (source) into unstable (Markus Koschany)
  • [2021-08-18] Accepted httpcomponents-core5 5.0.3-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Markus Koschany)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.4.3-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing