testcontainers / testcontainers/testcontainers-java

[Bug]: com.github.docker-java:docker-java-transport-zerodep pulls in apache httpcomponents which was tagged in CVE-2026-54428

Open
#11,973 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

security type/housekeeping
Dominant language
Java
Stars
8.7k
Forks
1.9k
Avg merge
2d 17h
Merged PRs (30d)
9

Description

Module

Core

Testcontainers version

2.05

Using the latest Testcontainers version?

Yes

Host OS

Mac

Host Arch

ARM

Docker version
Client: Docker Engine - Community
 Version:           29.6.2
 API version:       1.55
 Go version:        go1.26.5
 Git commit:        dfc4efb1e2
 Built:             Thu Jul 16 16:09:24 2026
 OS/Arch:           darwin/arm64
 Context:           desktop-linux

Server: Docker Desktop 4.83.0 (234302)
 Engine:
  Version:          29.6.2
  API version:      1.55 (minimum version 1.40)
  Go version:       go1.26.5
  Git commit:       3d80467
  Built:            Thu Jul 16 16:13:03 2026
  OS/Arch:          linux/arm64
  Experimental:     false
 containerd:
  Version:          v2.2.5
  GitCommit:        e53c7c1516c3b2bff98eb76f1f4117477e6f4e66
 runc:
  Version:          1.3.6
  GitCommit:        v1.3.6-0-g491b69ba
 docker-init:
  Version:          0.19.0
  GitCommit:        de40ad0
What happened?

Please fix the security vulnerability

Relevant log output

Additional Information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in the Core module by inspecting its dependency declarations and dependency tree for docker-java-transport-zerodep and Apache HTTP Components. Confirm which dependency introduces the vulnerable component, then verify that the resolved dependency is no longer affected and the Core module tests pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.