CVE-2026-64607
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Published:Jul 31, 2026
Last Modified:Aug 13, 2026
EPS:Jul 31, 2026
EPSS Score:0.00332
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Httpclient
Apache
Httpclient
Vendor
Apache
Product
Httpcomponents Client
Apache
Httpcomponents Client
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
