LOWVulnerability
CVE-2026-90455
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Properties
- cve_id
- CVE-2026-90455
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- published_at
- 2026-09-11T22:16:47.873
- last_modified
- 2026-09-18T19:40:31.053
Related Entities (1)
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph