Connection Management Flaw in Apache HttpComponents Client
CVE-2026-64607

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
31 July 2026

What is CVE-2026-64607?

A flaw exists in the Apache HttpComponents Client where the library fails to properly release connections back to the connection manager upon encountering an invalid or unsupported 'Content-Encoding' header in the HTTP response. This issue primarily impacts versions of the HttpClient based on the classic I/O model, potentially leading to resource exhaustion or connection leaks, thereby diminishing performance and reliability.

Affected Version(s)

Apache HttpComponents Client 5.0-alpha <= 5.6.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao <by111@126.com>
.