Vulnerabilities
Vulnerable Software
Apache:  >> Httpclient  >> 5.0.1  Security Vulnerabilities
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-07-31
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVSS Score
5.3
EPSS Score
0.087
Published
2020-12-02


Contact Us

Shodan ® - All rights reserved