Debian Package Tracker
Register | Log in
Subscribe

httpcomponents-core5

set of low level HTTP transport components for Java

Choose email to subscribe with

general
  • source: httpcomponents-core5 (main)
  • version: 5.4.3-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Markus Koschany [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 5.2.1-1
  • stable: 5.2.2-1
  • testing: 5.4.3-1
  • unstable: 5.4.3-1
versioned links
  • 5.2.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.2.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libhttpcore5-java
action needed
3 security issues in trixie high

There are 3 open security issues in trixie.

1 important issue:
  • CVE-2026-71290: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
2 issues left for the package maintainer to handle:
  • CVE-2026-54399: (needs triaging) Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
  • CVE-2026-54428: (needs triaging) Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-02 Last update: 2026-08-14 06:32
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-71290: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
Created: 2026-08-13 Last update: 2026-08-14 06:32
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-71290: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
Created: 2026-08-13 Last update: 2026-08-14 06:32
3 security issues in bookworm high

There are 3 open security issues in bookworm.

1 important issue:
  • CVE-2026-71290: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
2 issues postponed or untriaged:
  • CVE-2026-54399: (postponed; to be fixed through a stable update) Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
  • CVE-2026-54428: (postponed; to be fixed through a stable update) Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Created: 2026-08-13 Last update: 2026-08-14 06:32
news
[rss feed]
  • [2026-08-13] httpcomponents-core5 5.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-08] Accepted httpcomponents-core5 5.4.3-1 (source) into unstable (Jérôme Charaoui)
  • [2026-07-30] Accepted httpcomponents-core5 5.4.2-2 (source) into unstable (Jérôme Charaoui)
  • [2026-06-20] httpcomponents-core5 5.4.2-1.1 MIGRATED to testing (Debian testing watch)
  • [2026-06-15] Accepted httpcomponents-core5 5.4.2-1.1 (source) into unstable (Adrian Bunk)
  • [2026-03-17] Accepted httpcomponents-core5 5.4.2-1 (source) into unstable (Emmanuel Bourg)
  • [2026-02-15] httpcomponents-core5 5.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-09] Accepted httpcomponents-core5 5.4-1 (source) into unstable (Emmanuel Bourg)
  • [2025-11-03] httpcomponents-core5 5.2.2-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-29] Accepted httpcomponents-core5 5.2.2-2 (source) into unstable (Andrius Merkys)
  • [2023-09-16] httpcomponents-core5 5.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-11] Accepted httpcomponents-core5 5.2.2-1 (source) into unstable (Markus Koschany)
  • [2023-05-28] Accepted httpcomponents-core5 5.2.1-1~bpo11+1 (source) into bullseye-backports (Markus Koschany)
  • [2023-01-29] httpcomponents-core5 5.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-23] Accepted httpcomponents-core5 5.2.1-1 (source) into unstable (Markus Koschany)
  • [2022-11-19] httpcomponents-core5 5.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-13] Accepted httpcomponents-core5 5.2-1 (source) into unstable (Markus Koschany)
  • [2022-08-11] httpcomponents-core5 5.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-06] Accepted httpcomponents-core5 5.1.4-1 (source) into unstable (Markus Koschany)
  • [2022-01-06] Accepted httpcomponents-core5 5.1.3-1~bpo11+1 (source all) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-30] httpcomponents-core5 5.1.3-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-25] Accepted httpcomponents-core5 5.1.3-1 (source) into unstable (Markus Koschany)
  • [2021-12-24] Accepted httpcomponents-core5 5.1.2-2 (source) into unstable (Markus Koschany)
  • [2021-10-24] httpcomponents-core5 5.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-18] Accepted httpcomponents-core5 5.1.2-1 (source) into unstable (Markus Koschany)
  • [2021-08-26] httpcomponents-core5 5.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2021-08-20] Accepted httpcomponents-core5 5.0.3-2 (source) into unstable (Markus Koschany)
  • [2021-08-18] Accepted httpcomponents-core5 5.0.3-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Markus Koschany)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.4.3-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing