oss-sec mailing list archives

CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS


From: Oleg Kalnichevski <olegk () apache org>
Date: Thu, 13 Aug 2026 08:52:34 +0000

Severity: important 

Affected versions:

- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.0-alpha through 5.6.2

Description:

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection 
manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note 
this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Credit:

Yu Bao from PayPal Cyber Security Team (finder)

References:

https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q
https://hc.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-64607


Current thread: