CVE-2026-64607
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
| CWE | CWE-772 |
| Vendor | apache software foundation |
| Product | apache httpcomponents client |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache httpcomponents client
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache httpcomponents client are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache HttpComponents Client
5.0-alpha ≤ 5.6.2
References
Credits
Yu Bao <[email protected]>