CVE-2026-64607

ADVISORY - github

Summary

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

EPSS Score: 0.00332 (0.259)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Missing Release of Resource after Effective Lifetime

ADVISORY - github

Missing Release of Resource after Effective Lifetime


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in