CVE-2026-64607

EUVD-2026-51519
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 40.2%
Affected Products (NVD)
VendorProductVersion
apachehttpclient
5.0.0 ≤
𝑥
< 5.6.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
commons-httpclient
bookworm
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
httpcomponents-client
bookworm
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
commons-httpclient
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
httpcomponents-client
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage