CVE-2026-64607
ADVISORY - githubSummary
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.
This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Common Weakness Enumeration (CWE)
Missing Release of Resource after Effective Lifetime
Missing Release of Resource after Effective Lifetime
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-6655-wm2f-cqmx
-
minimos
MINI-2q5v-584p-6vj4
-
minimos
MINI-3p2c-82xr-jh42
-
minimos
MINI-4cfq-4qw9-hxgv
-
minimos
MINI-5324-q6pw-vfjm
-
minimos
MINI-573j-q8w8-wff5
-
minimos
MINI-c3v8-6vvp-m4v6
-
minimos
MINI-cvhh-fcxc-72g5
-
minimos
MINI-f538-p42q-qpqx
-
minimos
MINI-h7rp-cprf-f9vq
-
minimos
MINI-hgm2-rgp9-mxx4
-
minimos
MINI-j5rm-ppf4-wwcw
-
minimos
MINI-jfc7-39pr-rmr9
-
minimos
MINI-m7q7-wmrp-9gcf
-
minimos
MINI-pgc2-4q6q-r3qh
-
minimos
MINI-pmqr-v96g-w55c
-
minimos
MINI-qhp3-qwxg-xrff
-
minimos
MINI-vgx7-g3j6-23p6
-
minimos
MINI-vpxj-hc65-8mfw
-
minimos
MINI-wm66-r32w-gqg2
-
minimos
MINI-x2h3-2w74-jg45
-
minimos
MINI-xwmp-88gr-fqj6
-
minimos
MINI-xx69-jrqr-q8v7
-