Hi, could you fix the following vulnerability please?
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-71290
Even though the CVE is about Apache HttpComponents, our vulnerability scanner flagged split.io:java-client:4:18.3 also as vulnerable to it. A look into your sources shows that this is because Apache HttpComponent source files (from a vulnerable version) are copied into this project. I would advice you to simply use the latest Apache HttpComponent dependency instead.
Thank you and have a nice day!
Regards, Erik
Hi, could you fix the following vulnerability please?
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-71290
Even though the CVE is about Apache HttpComponents, our vulnerability scanner flagged split.io:java-client:4:18.3 also as vulnerable to it. A look into your sources shows that this is because Apache HttpComponent source files (from a vulnerable version) are copied into this project. I would advice you to simply use the latest Apache HttpComponent dependency instead.
Thank you and have a nice day!
Regards, Erik