Skip to content

CVE-2026-71290 #634

Description

@Ez2

Hi, could you fix the following vulnerability please?
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-71290

Even though the CVE is about Apache HttpComponents, our vulnerability scanner flagged split.io:java-client:4:18.3 also as vulnerable to it. A look into your sources shows that this is because Apache HttpComponent source files (from a vulnerable version) are copied into this project. I would advice you to simply use the latest Apache HttpComponent dependency instead.

Thank you and have a nice day!

Regards, Erik

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions