Severity: important 

Affected versions:

- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 
5.0-alpha through 5.6.2

Description:

HttpClient based on the classic i/o model fails to correctly release the 
underlying connection back to the connection manager if it encounters an 
invalid or unsupported `Content-Encoding` header value in the response message. 
Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Credit:

Yu Bao from PayPal Cyber Security Team (finder)

References:

https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q
https://hc.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-64607

Reply via email to