Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjcp-jmpx-g3qm

Опубликовано: 31 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

EPSS

Процентиль: 15%
0.00238
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-772

Связанные уязвимости

CVSS3: 5.3
nvd
4 дня назад

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CVSS3: 5.3
debian
4 дня назад

HttpClient based on the classic i/o model fails to correctly release t ...

EPSS

Процентиль: 15%
0.00238
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-772