CVE-2026-64607
ADVISORY - githubSummary
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.
This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Common Weakness Enumeration (CWE)
Missing Release of Resource after Effective Lifetime
Missing Release of Resource after Effective Lifetime
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-6655-wm2f-cqmx
-
minimos
MINI-3p2c-82xr-jh42
-
minimos
MINI-4cfq-4qw9-hxgv
-
minimos
MINI-573j-q8w8-wff5
-
minimos
MINI-cvhh-fcxc-72g5
-
minimos
MINI-f538-p42q-qpqx
-
minimos
MINI-h7rp-cprf-f9vq
-
minimos
MINI-hgm2-rgp9-mxx4
-
minimos
MINI-j5rm-ppf4-wwcw
-
minimos
MINI-pgc2-4q6q-r3qh
-
minimos
MINI-qhp3-qwxg-xrff
-
minimos
MINI-wm66-r32w-gqg2
-
minimos
MINI-xx69-jrqr-q8v7
-