[
https://issues.apache.org/jira/browse/GEODE-10590?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099800#comment-18099800
]
ASF subversion and git services commented on GEODE-10590:
---------------------------------------------------------
Commit e3cb1f02a2fa35456053a43036a8961f99fd1292 in geode's branch
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=e3cb1f02a2 ]
[GEODE-10590] Remediation of CVE-2026-54428 (#8016)
* Remediation of CVE-2026-54428
* CI build failure
> Remediation of CVE-2026-54428
> -----------------------------
>
> Key: GEODE-10590
> URL: https://issues.apache.org/jira/browse/GEODE-10590
> Project: Geode
> Issue Type: Improvement
> Reporter: Jinwoo Hwang
> Assignee: Jinwoo Hwang
> Priority: Major
>
> Affected versions of this package are vulnerable to Allocation of Resources
> Without Limits or Throttling due to the lack of enforced limits in the
> `HPackDecoder` process. An attacker can exhaust system memory by sending
> oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement
> applies the configured header list size limit.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)