Apache HttpComponents Client是美国Apache基金会的一款实现HTTP协议通信的客户端库。 Apache HttpComponents Client 5.0-alpha1版本至5.6.2版本存在资源管理错误漏洞,该漏洞源于遇到无效或不支持的Content-Encoding标头值时,基于经典I/O模型的HttpClient未能正确释放底层连接。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache HttpComponents Client | 5.0-alpha≤ 5.6.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache HttpComponents Client | 5.0-alpha ~ 5.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62391 | Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf a | |
| CVE-2026-44615 | Path traversal in NotebookRepo note and folder path composition |
No comments yet