CVE-2026-54428
HighAdvisory
Published 1 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.009
- 57th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 135
- of 17,781 indexed, latest versions
- Container images
- 159
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
Carried by container images the latest versions of 135 of 17,781 indexed charts deploy, on 159 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| httpcore5-h2maven | 5.0.1, 5.0.2, 5.1.1, 5.1.3+14 more | 5.4.3 | 159 |
- OSV records
- GHSA-v3jc-474w-2wm6
Charts affected
135 by stars
Container images carrying it
159 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| jacobalberty/ | 896c0ab82d33 | httpcore5-h2 | 5.4.3 | 3 |
| airbyte/ | 119be7bfb719 | httpcore5-h2 | 5.4.3 | 2 |
| apache/ | 0116fb802786 | httpcore5-h2 | 5.4.3 | 2 |
| apache/ | a83cf1980609 | httpcore5-h2 | 5.4.3 | 2 |
| graviteeio/ | 05fd67a93056 | httpcore5-h2 | 5.4.3 | 2 |
| graviteeio/ | 27374522cd04 | httpcore5-h2 | 5.4.3 | 2 |
| metabase/ | 9491ed11c901 | httpcore5-h2 | 5.4.3 | 2 |
| nacos/ | 1c191c30c8cd | httpcore5-h2 | 5.4.3 | 2 |
| ghcr.io/ | 536358d7b17e | httpcore5-h2 | 5.4.3 | 2 |
| ghcr.io/ | 3f2d14563495 | httpcore5-h2 | 5.4.3 | 2 |
| public.ecr.aws/ | b53a854bd7c1 | httpcore5-h2 | 5.4.3 | 2 |
| 2martens/ | bf1cdb80239d | httpcore5-h2 | 5.4.3 | 1 |
| 2martens/ | bd1ba6ab84c9 | httpcore5-h2 | 5.4.3 | 1 |
| 2martens/ | ba2c3040dab0 | httpcore5-h2 | 5.4.3 | 1 |
| ahmetfurkandemir/ | 142231a0b8b7 | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | f71cf4e185d5 | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | d42813fcc191 | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | d97b67a1346d | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | 70e125498a1c | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | 8060b88b29c8 | httpcore5-h2 | 5.4.3 | 1 |
| airbyte/ | 42093cff86e9 | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | 3aeaee66bc66 | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | 15ebb75b94dc | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | a6c1b933517f | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | 46ed5bcb04b2 | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | 5d4eab1c36b9 | httpcore5-h2 | 5.4.3 | 1 |
| aktosecurity/ | 498e3e35ecc2 | httpcore5-h2 | 5.4.3 | 1 |
| apache/ | 1f96558fd292 | httpcore5-h2 | 5.4.3 | 1 |
| apache/ | 0cef139b6bf1 | httpcore5-h2 | 5.4.3 | 1 |
| apache/ | 80136ae753ee | httpcore5-h2 | 5.4.3 | 1 |
| athou/ | 5e388351df1a | httpcore5-h2 | 5.4.3 | 1 |
| atlassian/ | 4af4bb6c8d46 | httpcore5-h2 | 5.4.3 | 1 |
| atlassian/ | 05933f2b1cfd | httpcore5-h2 | 5.4.3 | 1 |
| atlassian/ | c81cc7d6bc9e | httpcore5-h2 | 5.4.3 | 1 |
| atlassian/ | e5548cd4eea8 | httpcore5-h2 | 5.4.3 | 1 |
| bluerange/ | 07c8f73b55df | httpcore5-h2 | 5.4.3 | 1 |
| camunda/ | bcc5bb0542df | httpcore5-h2 | 5.4.3 | 1 |
| cbioportal/ | 08debbd2dbf9 | httpcore5-h2 | 5.4.3 | 1 |
| ckan/ | ef8e5d3e6be1 | httpcore5-h2 | 5.4.3 | 1 |
| cmosborn/ | 6ec0a8878ad2 | httpcore5-h2 | 5.4.3 | 1 |
| conductoross/ | 9fba127693e6 | httpcore5-h2 | 5.4.3 | 1 |
| confluentinc/ | f466f8649aa8 | httpcore5-h2 | 5.4.3 | 1 |
| confluentinc/ | 8ec46c27982f | httpcore5-h2 | 5.4.3 | 1 |
| confluentinc/ | ee403d5b9090 | httpcore5-h2 | 5.4.3 | 1 |
| confluentinc/ | f0cfd047a839 | httpcore5-h2 | 5.4.3 | 1 |
| dbeaver/ | 87ab86d00f8c | httpcore5-h2 | 5.4.3 | 1 |
| dependencytrack/ | 1ba4f004e1ec | httpcore5-h2 | 5.4.3 | 1 |
| dremio/ | 80ed2e3b7c43 | httpcore5-h2 | 5.4.3 | 1 |
| easypi/ | d2950a36a576 | httpcore5-h2 | 5.4.3 | 1 |
| eginnovations/ | e4dfe242fe9f | httpcore5-h2 | 5.4.3 | 1 |