THREAT OPS › Threat News › CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
<p>Posted by Oleg Kalnichevski on Aug 13</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.0-alpha through 5.6.2<br /> <br /> Description:<br /> <br /> HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection <br /> manager if it encounter
Indicators of compromise
- CVE-2026-64607cve
Original source: https://seclists.org/oss-sec/2026/q3/490