VYPR

apk package

chainguard/opensearch-fips-3-cross-cluster-replication

pkg:apk/chainguard/opensearch-fips-3-cross-cluster-replication

Vulnerabilities (4)

  • CVE-2026-64607MedJul 31, 2026
    affected < 3.8.0-r1fixed 3.8.0-r1

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas

  • CVE-2026-54428HigJul 1, 2026
    affected < 3.8.0-r1fixed 3.8.0-r1

    Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks

  • CVE-2026-54399HigJul 1, 2026
    affected < 3.8.0-r1fixed 3.8.0-r1

    Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of he

  • CVE-2026-40542HigApr 22, 2026
    affected < 3.6.0-r2fixed 3.6.0-r2

    Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.