# Security PSA: 16 Advisories in HTTP.jl (Please upgrade to 2.4.0)

**URL:** <https://discourse.julialang.org/t/security-psa-16-advisories-in-http-jl-please-upgrade-to-2-4-0/137705>\
**Category:** Community\
**Created:** [June 20, 2026, 2:26am UTC](https://discourse.julialang.org/t/security-psa-16-advisories-in-http-jl-please-upgrade-to-2-4-0/137705 "2026-06-20T02:26:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keno](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/keno/32/285_2.png) [@Keno](https://discourse.julialang.org/u/Keno)\
**Post date:** [June 20, 2026, 2:26am UTC](https://discourse.julialang.org/t/security-psa-16-advisories-in-http-jl-please-upgrade-to-2-4-0/137705/1 "2026-06-20T02:26:43Z")

</div>

We are in the process of publishing 16 advisories in HTTP.jl all of them fixed in the just-released HTTP.jl 2.4.0. See the SecurityAdvisories.jl repo ([Publish HTTP.jl security advisories - Pull Request #549 - JuliaLang/SecurityAdvisories.jl - GitHub](https://github.com/JuliaLang/SecurityAdvisories.jl/pull/549)) for details. None of these are particularly major by themselves, but as a set they add up, so we recommend all users upgrade as soon as possible.

These issues were detected by a version of Claude Mythos and disclosed to the Julia Security team by Anthropic’s Coordinated Vulnerability Disclosure team. We thank them for their efforts.

---

<div class="post-metadata">

**Author:** ![Keno](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/keno/32/285_2.png) [@Keno](https://discourse.julialang.org/u/Keno)\
**Post date:** [June 20, 2026, 2:27am UTC](https://discourse.julialang.org/t/security-psa-16-advisories-in-http-jl-please-upgrade-to-2-4-0/137705/2 "2026-06-20T02:27:27Z")

</div>

It’s been requested that I clarify that this is unrelated to the recent CI issues (which we are still in the process of fully resolving and will have a separate writeup once fully complete).

---

<div class="post-metadata">

**Author:** ![hhaensel](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/hhaensel/32/1207_2.png) [@hhaensel](https://discourse.julialang.org/u/hhaensel)\
**Post date:** [June 23, 2026, 6:02am UTC](https://discourse.julialang.org/t/security-psa-16-advisories-in-http-jl-please-upgrade-to-2-4-0/137705/3 "2026-06-23T06:02:34Z")

</div>

Has the `Downloads.jl` package also been scanned for vulnerabilities?
