[ 
https://issues.apache.org/jira/browse/GEODE-10590?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099800#comment-18099800
 ] 

ASF subversion and git services commented on GEODE-10590:
---------------------------------------------------------

Commit e3cb1f02a2fa35456053a43036a8961f99fd1292 in geode's branch 
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=e3cb1f02a2 ]

[GEODE-10590] Remediation of CVE-2026-54428 (#8016)

* Remediation of CVE-2026-54428

* CI build failure

> Remediation of CVE-2026-54428
> -----------------------------
>
>                 Key: GEODE-10590
>                 URL: https://issues.apache.org/jira/browse/GEODE-10590
>             Project: Geode
>          Issue Type: Improvement
>            Reporter: Jinwoo Hwang
>            Assignee: Jinwoo Hwang
>            Priority: Major
>
> Affected versions of this package are vulnerable to Allocation of Resources 
> Without Limits or Throttling due to the lack of enforced limits in the 
> `HPackDecoder` process. An attacker can exhaust system memory by sending 
> oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement 
> applies the configured header list size limit.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to