LOWVulnerability

CVE-2026-90455

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.

Properties

cve_id
CVE-2026-90455
signal_observed_at
2026-09-21T23:07:07+00:00
published_at
2026-09-11T22:16:47.873
last_modified
2026-09-18T19:40:31.053

Related Entities (1)

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90455 — Ninja Signal Threat Intelligence | Ninja Signal