Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Дата публикации: 13-08-2026 21:29:30

Posted by Oleg Kalnichevski on Aug 13Severity: important
Affected versions:
- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.0-alpha through 5.6.2
Description:
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection
manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note
this defect does not affect HttpClient based on...


Основное содержимое страницы с новостью.

oss-sec logo oss-sec mailing list archives CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
From: Oleg Kalnichevski <olegk () apache org>
Date: Thu, 13 Aug 2026 08:52:34 +0000

Severity: important 

Affected versions:

- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.0-alpha through 5.6.2

Description:

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection 
manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note 
this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Credit:

Yu Bao from PayPal Cyber Security Team (finder)

References:

https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q
https://hc.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-64607


Current thread:
  • CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Oleg Kalnichevski (Aug 13)

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document013.1313-08-2026
2OpenSSL Security Advisory06.6213-08-2026
3Re: GNU Inetutils talkd buffer overflow with long DNS names.08.8615-08-2026
4CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for011.5413-08-2026
5CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse09.6915-08-2026
6CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse08.7515-08-2026
7CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send09.515-08-2026
8Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands04.7128-07-2026
9How to detect HTTP/2 abuse in Apache web server logs010.9727-05-2026
10🚨 Patch-Stress im Mai 2026027.809-05-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.41. Источник: seclists.org.