StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3

Open the chart page →

1,689
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
httpclient5@5.4.3
5.6.3

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3

Open the chart page →

9,397
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3

Open the chart page →

1,639
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient5@5.2.1
5.6.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3

Open the chart page →

6,016

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dbeaver/cloudbeaver:26.1.287ab86d00f8c
httpclient5@5.4.4
5.6.3
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
httpclient5@5.6.1
5.6.3
1
dependencytrack/apiserver:latestf1da63ed610a
httpclient5@5.6.2
5.6.3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient5@5.1.3
5.6.3
1
easypi/openrefine:3.7.0d2950a36a576
httpclient5@5.2.1
5.6.3
1
eginnovations/agent:7.5.4e4dfe242fe9f
httpclient5@5.3.1
5.6.3
1
erudikaltd/para:latest_stable235e0bc53da2
httpclient5@5.6.1
5.6.3
1
erudikaltd/scoold:1.66.0949c56b57e8f
httpclient5@5.5.2
5.6.3
1
factorhouse/factor-platform:96.414728f9fd80f
httpclient5@5.6.2
5.6.3
1
factorhouse/flex:96.41f884dde506d
httpclient5@5.6.2
5.6.3
1
factorhouse/flex-ce:96.4c67def40a689
httpclient5@5.6.2
5.6.3
1
factorhouse/kpow:96.4f9ce9b16b3a7
httpclient5@5.6.2
5.6.3
1
factorhouse/kpow-ce:96.466b08cc9e943
httpclient5@5.6.2
5.6.3
1
flowable/flowable-rest:7.1.0b7ae287502cd
httpclient5@5.3.1
5.6.3
1
folioci/edge-caiasoft:latestc3cfa89eee2f
httpclient5@5.6.1
5.6.3
1
folioci/edge-dematic:latest48c9b1d180d4
httpclient5@5.6.1
5.6.3
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
httpclient5@5.6.1
5.6.3
1
folioci/edge-rtac:latest15ef73b1abd0
httpclient5@5.5.2
5.6.3
1
folioci/mod-calendar:latest22f65982efd7
httpclient5@5.0.3
5.6.3
1
folioci/mod-copycat:latest1513fad2b799
httpclient5@5.5.1
5.6.3
1
folioci/mod-email:latest79ea8e2e7ebf
httpclient5@5.0.3
5.6.3
1
folioci/mod-ncip:latest8ed83674352b
httpclient5@5.2.1
5.6.3
1
folioci/mod-password-validator:latestb31d75f2bf7b
httpclient5@5.5.1
5.6.3
1
folioci/mod-search:latest44d7ee9acdf6
httpclient5@5.6.1
5.6.3
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
httpclient5@5.4.4
5.6.3
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
httpclient5@5.4.4
5.6.3
1
glarad/mc-service-registry:latest7b02b9e7f1ef
httpclient5@5.5.2
5.6.3
1
graylog/graylog:7.1.9598bd41fefd5
httpclient5@5.5.1
5.6.3
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
httpclient5@5.5.1
5.6.3
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
httpclient5@5.5.2
5.6.3
1
gridgain/gridgain9:9.1.1895018390077b
httpclient5@5.6
5.6.3
1
hazelcast/hazelcast-enterprise:5.7.1cf244da155eb
httpclient5@5.6.2
5.6.3
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
httpclient5@5.2.1
5.6.3
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
httpclient5@5.1.3
5.6.3
1
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient5@5.3
5.6.3
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
httpclient5@5.4.4
5.6.3
1
kubebb/mesh-api:v5.7.0a3879931dfa1
httpclient5@5.2.1
5.6.3
1
labs64/auditflowc7b26d3ca11c
httpclient5@5.5.1
5.6.3
1
labs64/payment-gateway:0.0.10c66feefca17
httpclient5@5.5.1
5.6.3
1
library/elasticsearch:9.5.19656a9ca03f8
httpclient5@5.6.1
5.6.3
1
library/xwiki:lts-postgres-tomcat56490ac14a31
httpclient5@5.5.1
5.6.3
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient5@5.5.2
5.6.3
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
httpclient5@5.2.1
5.6.3
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
httpclient5@5.2.1
5.6.3
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
httpclient5@5.2.1
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.