Zurück zur CVE-Übersicht
CVE-2026-64607
MEDIUM(5.3)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Risk Signal Score13/100 — NIEDRIG
- CVSS 5.3 — Mittel
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.5%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
5.3
Technische Schwere
Beschreibung
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Betroffene Produkte
- cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*
GitHub Advisories
GHSA-hjcp-jmpx-g3qmMEDIUM
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
maven/org.apache.httpcomponents.client5:httpclient5→ 5.6.3
GitHub Advisory