Skip to content

Upgrade apache httpcomponents core5 due to High Vulnerability - #1961

Open
igordayen wants to merge 1 commit into
mainfrom
httpcomponents-high-vulnerability
Open

Upgrade apache httpcomponents core5 due to High Vulnerability#1961
igordayen wants to merge 1 commit into
mainfrom
httpcomponents-high-vulnerability

Conversation

@igordayen

Copy link
Copy Markdown
Contributor

Overview

Upgraded

org.apache.httpcomponents.core5:httpcore5
and
org.apache.httpcomponents.core5:httpcore5-h2

to version 5.4.3

Due to high vulnerability:

git/embabel-agent$ mvn dependency:tree|grep core5
[INFO] |  |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:runtime
[INFO] |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:runtime
[INFO] |  |  |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:runtime (optional)
[INFO] |  |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:runtime (optional)
[INFO] |  |     +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:compile
[INFO] |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:compile
[INFO] |  |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:runtime
[INFO] |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:runtime
[INFO] |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:test
[INFO] |  +- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:test
[INFO] |  |  |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:runtime
[INFO] |  |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:runtime
[INFO] |     |     +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:compile
[INFO] |     |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:compile
[INFO] |  |  |  +- org.apache.httpcomponents.core5:httpcore5:jar:5.4.3:runtime
[INFO] |  |  |     \- org.apache.httpcomponents.core5:httpcore5-h2:jar:5.4.3:runtime

@igordayen
igordayen requested a review from alexheifetz August 21, 2026 03:25
@igordayen igordayen added this to the 1.5.1-Release🔵 milestone Aug 21, 2026
@igordayen igordayen added the vulnerability Reported CVE, introduced via direct or transitive reference. label Aug 21, 2026
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

vulnerability Reported CVE, introduced via direct or transitive reference.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant