Missing Release of Resource after Effective Lifetime in Apache HttpComponents Client - CVE-2026-64607
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the classic i/o model HttpClient connection handling when processing a response with an invalid or unsupported content-encoding header value. A remote attacker can send a response with an invalid or unsupported content-encoding header value to cause a denial of service.
Only the classic i/o model is affected; the async i/o model is not affected.
Affected software
IBM App Connect Enterprise
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
IBM Content Navigator
Informix Dynamic Server
httpcomponents-client
How to mitigate CVE-2026-64607
IBM Content Navigator - addressed in versions 3.1.0 IF013, 3.2.0 IF008, 26.0.0 IF003
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16
IBM App Connect Enterprise - update to 13.0.8.2
httpcomponents-client - update to 4.5.14-150200.3.12.1