Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-64607

Опубликовано: 31 июл. 2026
Источник: debian
EPSS Низкий

Описание

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
httpcomponents-clientundeterminedpackage
commons-httpclientundeterminedpackage

Примечания

  • https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q

EPSS

Процентиль: 15%
0.00238
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
4 дня назад

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CVSS3: 5.3
github
4 дня назад

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

EPSS

Процентиль: 15%
0.00238
Низкий