🔐 CVE Alert

CVE-2026-64607

UNKNOWN 0.0

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CWE CWE-772
Vendor apache software foundation
Product apache httpcomponents client
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache httpcomponents client

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache httpcomponents client are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache HttpComponents Client
5.0-alpha ≤ 5.6.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q

Credits

Yu Bao <[email protected]>