Package
zaproxy
Component
httpcore5-h2
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The CVE GHSA-v3jc-474w-2wm6 (httpcore5-h2 < 5.4.3) is the result of a pre-built binary plugin that is downloaded at build time from the ZAP plugin repository, not built from the zaproxy source code. As a result, there is no dependency we can bump to remediate. The fix requires an upstream release of the ZAP network plugin with the appropriate dependency upgraded.
Status