CVE-2026-64607
ADVISORY - githubSummary
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.
This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
EPSS Score: 0.00332 (0.259)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Missing Release of Resource after Effective Lifetime
ADVISORY - github
Missing Release of Resource after Effective Lifetime
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in