SCA: security update for org.http4k:http4k-core (GHSA-g4w2-6h2r-3m3w)

high Tenable Cloud Security Plugin ID 446037

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0,
ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions
impose no limit on decompressed size. An unauthenticated client can send a small gzip-encoded request body
that expands to gigabytes, exhausting the JVM heap and denying service to other clients. The fix uses
SizeLimitedInputStream to enforce a default 10 MiB limit, causes ServerFilters.GZip and
RequestFilters.GunZip to return 413 Request Entity Too Large, and causes other decompression paths to
throw SizeLimitExceededException. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.49.0.0.
(CVE-2026-53659)

Solution

Update the org.http4k:http4k-core library and its related packages to version 5.42.0.0 or later.

See Also

https://github.com/advisories/GHSA-g4w2-6h2r-3m3w

Plugin Details

Severity: High

ID: 446037

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 8/18/2026

Updated: 9/15/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53659

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/17/2026

Vulnerability Publication Date: 8/17/2026

Reference Information

CVE: CVE-2026-53659

cwe: CWE-409