This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hjcp-jmpx-g3qm | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS |
Thu, 13 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache httpcomponents Client |
|
| Vendors & Products |
Apache
Apache httpcomponents Client |
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 31 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2. | |
| Title | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS | |
| Weaknesses | CWE-772 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-13T16:18:20.395Z
Reserved: 2026-07-20T08:23:45.493Z
Link: CVE-2026-64607
Updated: 2026-08-13T16:18:20.395Z
Status : Modified
Published: 2026-07-31T11:17:11.710
Modified: 2026-08-13T17:17:33.733
Link: CVE-2026-64607
No data.
OpenCVE Enrichment
Updated: 2026-08-02T20:32:55Z
Github GHSA