GHSA-hjcp-jmpx-g3qm

    Dashboard / Vulnerabilities / GHSA-hjcp-jmpx-g3qm

    GHSA-hjcp-jmpx-g3qm

    Published: 31 Jul 2026Last Modified: 10 Sept 2026

    Summary: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

    Details: HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

    Affected packages

    Package

    Name: org.apache.httpcomponents.client5:httpclient5

    Purl: pkg:maven/org.apache.httpcomponents.client5/httpclient5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.0-alpha1
    Fixed -5.6.3

    Affected versions

    5.0
    5.0.1
    5.0.2
    5.0.3
    5.0.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hjcp-jmpx-g3qm | CVE-DB