SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-64607

MEDIUM · CVSS 5.3 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

Apache HttpComponents Client versions 5.0-alpha1 through 5.6.2 are vulnerable due to improper handling of invalid or unsupported `Content-Encoding` header values, which prevents the underlying connection from being released back to the connection manager. This can lead to resource exhaustion and potential denial of service. Organizations using the affected versions should prioritize patching to mitigate these risks, especially those relying on the classic I/O model for their applications.

CVE
CVE-2026-64607
Severity
MEDIUM
CVSS
5.3
EPSS
0.48%
Apache

Original NVD Description

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)