MEDIUM🇵🇱 Wersja polska

CVE-2026-64607

CVSS 5.3v3.1pub. 2026-07-31upd. 2026-08-13

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Apache Httpclient

    APP
    Apache
    5.0.0 – 5.6.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-71290CRITICAL9.1same product

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific...

CVE-2013-4366CRITICAL9.8PL ✓same product

Apache HttpClient 4.3.x — brak weryfikacji X509HostnameVerifier (null pointer)

CVE-2026-40542HIGH7.3same product

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to acc...

CVE-2025-27820HIGH7.5same product

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management a...

CVE-2020-13956MEDIUM5.3same product

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in...