Repository navigation
[fix][sec] Pin httpclient5 to 5.6.4 and httpcore5 to 5.4.3 - #26331
Merged
Merged
Conversation
Apache HttpComponents 5 enters the build transitively through com.yahoo.athenz:athenz-zts-java-client, which requests httpclient5 5.6.1 and (via its parent POM) httpcore5 / httpcore5-h2 5.4. Those versions are affected by CVE-2026-64607 (httpclient5) and CVE-2026-54428 / CVE-2026-54399 (httpcore5). Add version catalog entries for org.apache.httpcomponents.client5:httpclient5, org.apache.httpcomponents.core5:httpcore5 and org.apache.httpcomponents.core5:httpcore5-h2. The pulsar-dependencies enforced platform turns every catalog library into a constraint, so the catalog entries alone pin the transitive resolution across the build. httpcore5-h2 is pinned alongside httpcore5 since httpclient5 pulls it in and both ship from the same release train. Assisted-by: Claude Code (Opus 5)
nodece
approved these changes
Aug 14, 2026
Member
Author
|
Not needed in 4.0.x/4.2.x branches since athenz plugin version is older in those branches and it doesn't use httpclient5. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Apache HttpComponents 5 enters the build transitively through
com.yahoo.athenz:athenz-zts-java-client:1.12.42, which is a dependency of the two Athenz auth plugins (pulsar-client-auth-athenz,pulsar-broker-auth-athenz).It requested versions that are affected by published CVEs:
org.apache.httpcomponents.client5:httpclient5athenz-zts-java-client:1.12.42org.apache.httpcomponents.core5:httpcore5httpclient5-parent:5.6.1org.apache.httpcomponents.core5:httpcore5-h2httpclient5-parent:5.6.1httpcore5)Neither artifact had a version catalog entry, so nothing constrained them and the transitive request won.
Note this is distinct from the HttpComponents 4.x artifacts (
org.apache.httpcomponents:httpclient/:httpcore), which are already pinned in the catalog and are not changed here.Modifications
Added version catalog entries for the three artifacts in
gradle/libs.versions.toml:That is the entire change. The
pulsar-dependenciesenforced platform iterates every catalog library and turns it into a version constraint (the Gradle equivalent of Maven'sdependencyManagement), so adding the catalog entries pins the transitive resolution build-wide — no per-module dependency declarations are needed.httpcore5-h2is pinned alongsidehttpcore5becausehttpclient5pulls it in and both ship from the same release train; pinning onlyhttpcore5would have lefthttpcore5-h2behind on 5.4.Both target versions are the newest stable releases in their respective lines on Maven Central (
5.7-alpha1and5.5-beta2are pre-release).No LICENSE file changes are required. The Athenz auth plugins are not bundled in any distribution, so no HttpComponents 5 jar ships in a binary distribution — see Verifying this change below.
Verifying this change
This change is a dependency version pin without new test coverage. It was verified as follows:
Resolution, build-wide. Scanned every resolvable configuration in every project via an init script. The Athenz plugins are the only consumers, and all four classpaths (
compileClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath) in both modules now resolvehttpclient5:5.6.4,httpcore5:5.4.3andhttpcore5-h2:5.4.3.dependencyInsightreports the selection reason as "By constraint, Forced", over the5.6.1request fromathenz-zts-java-client.Compilation and tests.
:pulsar-client-auth-athenz:testand:pulsar-broker-auth-athenz:testpass against the pinned versions.Binary LICENSE.
checkBinaryLicensepasses for:distribution:pulsar-server-distributionand:distribution:pulsar-shell-distribution(the only two modules applyingpulsar.binary-license-check-conventions). Inspecting the built tarballs directly confirms the reason: the server distribution ships only the 4.x artifacts (httpclient-4.5.14.jar,httpcore-4.4.16.jar, already listed inLICENSE.bin.txt) and nohttpclient5/httpcore5/httpcore5-h2jar appears in either tarball.quickCheckandspotlessCheck checkstyleMain checkstyleTestpass.For completeness: the other path by which HttpComponents 5 could reach a classpath is
org.apache.thrift:libthriftviadistributedlog-core, but a component metadata rule inpulsar.java-conventions.gradle.ktsalready strips those dependencies, so it is unaffected either way.Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes
httpclient55.6.1 → 5.6.4 andhttpcore5/httpcore5-h25.4 → 5.4.3, both patch-level bumps within the same minor line, affecting only the Athenz auth plugin classpaths.