Severity: important Affected versions:
- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.0-alpha through 5.6.2 Description: HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2. Credit: Yu Bao from PayPal Cyber Security Team (finder) References: https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q https://hc.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-64607
