StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
httpclient5@5.0.3
5.6.3

Open the chart page →

415
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
httpclient5@5.5.1
5.6.3

Open the chart page →

1,466
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
httpclient5@5.0.3
5.6.3

Open the chart page →

866
mod-ncipfolio-org0.1.341 of 1See more

mod-ncip folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-ncip:latest8ed83674352b
httpclient5@5.2.1
5.6.3

Open the chart page →

1,103
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
httpclient5@5.5.1
5.6.3

Open the chart page →

394
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
httpclient5@5.6.1
5.6.3

Open the chart page →

1,531
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
httpclient5@5.1.3
5.6.3

Open the chart page →

34,754
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient5@5.6.1
5.6.3

Open the chart page →

4,556
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
httpclient5@5.5.2
5.6.3

Open the chart page →

1,691
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
httpclient5@5.6
5.6.3

Open the chart page →

3,199
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
httpclient5@5.2.1
5.6.3

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
httpclient5@5.5.1
5.6.3

Open the chart page →

8,541
kibanahelmforgeVerified publisher1.1.71 of 3See more

kibana helmforge 1.1.7

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.19656a9ca03f8
httpclient5@5.6.1
5.6.3

Open the chart page →

341
openbashelm-openbasVerified publisher1.8.142 of 7See more

openbas helm-openbas 1.8.14

2 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
httpclient5@5.3.1
5.6.3
opensearchproject/opensearch:3.3.2798cf28e226a
httpclient5@5.4.4
5.6.3

Open the chart page →

25,017
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient5@5.1.3
5.6.3

Open the chart page →

37,671
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
httpclient5@5.2.1
5.6.3

Open the chart page →

1,754
daveit-at-mOfficialVerified publisher0.2.154 of 11See more

dave it-at-m 0.2.15

4 of the 11 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
httpclient5@5.5.2
5.6.3

Open the chart page →

15,089
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient5@5.3.1
5.6.3

Open the chart page →

7,268
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat56490ac14a31
httpclient5@5.5.1
5.6.3

Open the chart page →

1,595
kron-aapm-agentkron-pam-aapm-helmcharts1.2.51 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.41cc7d5be6529
httpclient5@5.4.4
5.6.3

Open the chart page →

2,707
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
httpclient5@5.2.1
5.6.3

Open the chart page →

6,490
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
httpclient5@5.6.1
5.6.3

Open the chart page →

3,818
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
httpclient5@5.2.1
5.6.3

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
httpclient5@5.2.1
5.6.3

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
httpclient5@5.2.1
5.6.3

Open the chart page →

4,599
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
httpclient5@5.6
5.6.3

Open the chart page →

3,687
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
httpclient5@5.4.2
5.6.3

Open the chart page →

1,783
dependency-tracknaj980.0.91 of 3See more

dependency-track naj98 0.0.9

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dependencytrack/apiserver:latestf1da63ed610a
httpclient5@5.6.2
5.6.3

Open the chart page →

2,465
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
httpclient5@5.3.1
5.6.3

Open the chart page →

2,049
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpclient5@5.1.3
5.6.3

Open the chart page →

5,826
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
httpclient5@5.3.1
5.6.3

Open the chart page →

6,338
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
httpclient5@5.2.1
5.6.3

Open the chart page →

2,024
cp-cmfopenshift2.4.11 of 1See more

cp-cmf openshift 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.1f466f8649aa8
httpclient5@5.5.2
5.6.3

Open the chart page →

179
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.6.3

Open the chart page →

7,792
trinoopstty0.2.121 of 1See more

trino opstty 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
httpclient5@5.6.1
5.6.3

Open the chart page →

1,158
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
httpclient5@5.4.4
5.6.3

Open the chart page →

71,208
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
httpclient5@5.2.1
5.6.3

Open the chart page →

2,264
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
httpclient5@5.2.1
5.6.3

Open the chart page →

1,995
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient5@5.5.2
5.6.3

Open the chart page →

3,642
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
httpclient5@5.3.1
5.6.3

Open the chart page →

21,211
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
httpclient5@5.0.3
5.6.3

Open the chart page →

5,269
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
httpclient5@5.5.2
5.6.3

Open the chart page →

6,207
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
httpclient5@5.0.3
5.6.3

Open the chart page →

6,443
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
httpclient5@5.1
5.6.3

Open the chart page →

13,767
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
httpclient5@5.3.1
5.6.3

Open the chart page →

4,674
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
yuzutech/kroki:0.17.0192b7b27c857
httpclient5@5.1.3
5.6.3

Open the chart page →

8,715
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
httpclient5@5.1.3
5.6.3
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
httpclient5@5.1.3
5.6.3
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
httpclient5@5.1.3
5.6.3
thingsboard/tb-node:3.4.1645f43b688f7
httpclient5@5.1.3
5.6.3

Open the chart page →

25,394
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
httpclient5@5.5
5.6.3

Open the chart page →

7,637
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
httpclient5@5.3.1
5.6.3

Open the chart page →

2,144
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
httpclient5@5.5
5.6.3

Open the chart page →

1,527

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dbeaver/cloudbeaver:26.1.287ab86d00f8c
httpclient5@5.4.4
5.6.3
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
httpclient5@5.6.1
5.6.3
1
dependencytrack/apiserver:latestf1da63ed610a
httpclient5@5.6.2
5.6.3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient5@5.1.3
5.6.3
1
easypi/openrefine:3.7.0d2950a36a576
httpclient5@5.2.1
5.6.3
1
eginnovations/agent:7.5.4e4dfe242fe9f
httpclient5@5.3.1
5.6.3
1
erudikaltd/para:latest_stable235e0bc53da2
httpclient5@5.6.1
5.6.3
1
erudikaltd/scoold:1.66.0949c56b57e8f
httpclient5@5.5.2
5.6.3
1
factorhouse/factor-platform:96.414728f9fd80f
httpclient5@5.6.2
5.6.3
1
factorhouse/flex:96.41f884dde506d
httpclient5@5.6.2
5.6.3
1
factorhouse/flex-ce:96.4c67def40a689
httpclient5@5.6.2
5.6.3
1
factorhouse/kpow:96.4f9ce9b16b3a7
httpclient5@5.6.2
5.6.3
1
factorhouse/kpow-ce:96.466b08cc9e943
httpclient5@5.6.2
5.6.3
1
flowable/flowable-rest:7.1.0b7ae287502cd
httpclient5@5.3.1
5.6.3
1
folioci/edge-caiasoft:latestc3cfa89eee2f
httpclient5@5.6.1
5.6.3
1
folioci/edge-dematic:latest48c9b1d180d4
httpclient5@5.6.1
5.6.3
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
httpclient5@5.6.1
5.6.3
1
folioci/edge-rtac:latest15ef73b1abd0
httpclient5@5.5.2
5.6.3
1
folioci/mod-calendar:latest22f65982efd7
httpclient5@5.0.3
5.6.3
1
folioci/mod-copycat:latest1513fad2b799
httpclient5@5.5.1
5.6.3
1
folioci/mod-email:latest79ea8e2e7ebf
httpclient5@5.0.3
5.6.3
1
folioci/mod-ncip:latest8ed83674352b
httpclient5@5.2.1
5.6.3
1
folioci/mod-password-validator:latestb31d75f2bf7b
httpclient5@5.5.1
5.6.3
1
folioci/mod-search:latest44d7ee9acdf6
httpclient5@5.6.1
5.6.3
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
httpclient5@5.4.4
5.6.3
1
glarad/mc-service-registry:latest7b02b9e7f1ef
httpclient5@5.5.2
5.6.3
1
graylog/graylog:7.1.9598bd41fefd5
httpclient5@5.5.1
5.6.3
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
httpclient5@5.5.1
5.6.3
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
httpclient5@5.5.2
5.6.3
1
gridgain/gridgain9:9.1.1895018390077b
httpclient5@5.6
5.6.3
1
hazelcast/hazelcast-enterprise:5.7.1cf244da155eb
httpclient5@5.6.2
5.6.3
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
httpclient5@5.2.1
5.6.3
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
httpclient5@5.1.3
5.6.3
1
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient5@5.3
5.6.3
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
httpclient5@5.4.4
5.6.3
1
kubebb/mesh-api:v5.7.0a3879931dfa1
httpclient5@5.2.1
5.6.3
1
labs64/auditflowc7b26d3ca11c
httpclient5@5.5.1
5.6.3
1
labs64/payment-gateway:0.0.10c66feefca17
httpclient5@5.5.1
5.6.3
1
library/elasticsearch:9.5.19656a9ca03f8
httpclient5@5.6.1
5.6.3
1
library/xwiki:lts-postgres-tomcat56490ac14a31
httpclient5@5.5.1
5.6.3
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient5@5.5.2
5.6.3
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
httpclient5@5.2.1
5.6.3
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
httpclient5@5.2.1
5.6.3
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
httpclient5@5.2.1
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.