CVE-2026-90455EPSS p8.8%
CVE-2026-90455CVE-2026-90455
Description
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.20% probability of exploitation · percentile 8.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |