CVE-2026-64607
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
CVSS Score
5.3
EPSS Score
0.3%
EPSS Percentile
26th
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
| CWE | CWE-772 |
| Vendor | apache software foundation |
| Product | apache httpcomponents client |
| Published | Jul 31, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache httpcomponents client
Be the first to know when new medium vulnerabilities affecting apache software foundation apache httpcomponents client are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache HttpComponents Client
5.0-alpha ≤ 5.6.2
References
Credits
Yu Bao from PayPal Cyber Security Team