Skip to content

Bump httpclient5 5.3.1 -> 5.6.4, httpcore5/httpcore5-h2 -> 5.4.3 - #389

Merged
adimiz1 merged 1 commit into
masterfrom
bump-httpclient5-5.6.4
Sep 28, 2026
Merged

adimiz1 merged 1 commit into
masterfrom
bump-httpclient5-5.6.4

Conversation

@adimiz1

@adimiz1 adimiz1 commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bump httpclient5 5.3.1 -> 5.6.4 and httpcore5 5.3.5 -> 5.4.3.
  • Pin httpcore5-h2 5.4.3 explicitly. It was still resolving transitively to 5.2.4 through httpclient5 5.3.1, so the earlier httpcore5 bump did not fix the h2 CVE.
  • Update the ApacheHttpClient/<version> user-agent default in ApiStrategy and UploaderStrategy to 5.6.4.

httpclient5 5.6.4 is built against httpcore 5.4.3 and still targets Java 1.8.

Tickets

  • VIDEO-20814: DoS in httpcore5-h2 (needs >= 5.3.5)
  • VIDEO-20995: HPACK unbounded allocation in httpcore5-h2 (needs >= 5.4.2)
  • VIDEO-20996: HTTP/1.1 header parsing unbounded allocation in httpcore5-h2 (needs >= 5.4.2)
  • VIDEO-21159: classic ContentCompressionExec leaks pooled connections (needs >= 5.6.3)
  • VIDEO-21177: CVE-2026-71290, async hostname verification in 5.4-alpha to 5.6.3 (floor 5.6.4)

Test plan

  • dependencies --configuration runtimeClasspath: httpcore5 and httpcore5-h2 resolve only to 5.4.3
  • Compiles on JDK 8 (only the existing setConnectTimeout deprecation notes)
  • core: 275 tests, 0 failures
  • http5: 206 tests, 0 failures, 39 skipped (same skips as before)
  • CI matrix green

CHANGELOG will be updated at release time.

🤖 Generated with Claude Code

Pin httpcore5-h2 explicitly so it no longer resolves to 5.2.4
transitively. Update the ApacheHttpClient user-agent version to match.

Fixes VIDEO-20814, VIDEO-20995, VIDEO-20996, VIDEO-21159, VIDEO-21177.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@adimiz1
adimiz1 merged commit d0bc2fd into master Sep 28, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants