Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64607

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

A flaw was found in Apache HttpComponents Client, specifically in its classic input/output (I/O) model. When processing a response message with an invalid or unsupported Content-Encoding header, the client fails to properly release the underlying network connection. This connection leak can lead to the exhaustion of the connection pool, making the service unavailable and resulting in a Denial of Service (DoS) for legitimate users.

Отчет

This is an Important flaw in Apache HttpComponents Client's classic I/O model, where an invalid Content-Encoding header in a response can prevent proper connection release. This connection leak can exhaust the connection pool, leading to a denial of service for applications utilizing the affected client. The vulnerability does not impact the asynchronous I/O model.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9Affected
Red Hat build of Apache Camel 4 for Quarkus 3camel-quarkus-support-httpclient5Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2509736org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak

EPSS

Процентиль: 40%
0.00482
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CVSS3: 5.3
nvd
около 1 месяца назад

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

CVSS3: 5.3
debian
около 1 месяца назад

HttpClient based on the classic i/o model fails to correctly release t ...

CVSS3: 5.3
github
около 1 месяца назад

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

EPSS

Процентиль: 40%
0.00482
Низкий

7.5 High

CVSS3