StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3

Open the chart page →

1,689
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
httpclient5@5.4.3
5.6.3

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3

Open the chart page →

9,397
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3

Open the chart page →

1,639
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient5@5.2.1
5.6.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3

Open the chart page →

6,016

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
metabase/metabase:v0.63.1.124f150effd484
httpclient5@5.6.2
5.6.3
1
nacos/nacos-server:v3.0.20e951a1d07bb
httpclient5@5.4.2
5.6.3
1
nacos/nacos-server:v3.0.130a39cb0c54d
httpclient5@5.4.2
5.6.3
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpclient5@5.1.3
5.6.3
1
olvid/bot-daemon:2.0.1e0e6b165d879
httpclient5@5.3.1
5.6.3
1
openbas/platform:2.0.5d986d80b0a75
httpclient5@5.3.1
5.6.3
1
opennms/sentinel:36.0.288869082a14f
httpclient5@5.2.1
5.6.3
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
httpclient5@5.3.1
5.6.3
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
httpclient5@5.4.4
5.6.3
1
opensearchproject/opensearch:2.19.269588c664014
httpclient5@5.3.1
5.6.3
1
opensearchproject/opensearch:3.3.2798cf28e226a
httpclient5@5.4.4
5.6.3
1
opensearchproject/opensearch:2.19.68690b204fe91
httpclient5@5.4.3
5.6.3
1
penpotapp/backend:2.17.2770b55f6e51b
httpclient5@5.6.1
5.6.3
1
reportportal/service-api:5.15.4bf193091525a
httpclient5@5.4.3
5.6.3
1
reportportal/service-authorization:5.15.16a954407b417
httpclient5@5.5.1
5.6.3
1
resurfaceio/resurface:3.7.84d5cda2f64109
httpclient5@5.4.2
5.6.3
1
stardog/stardog:latest2714e5c4b3c1
httpclient5@5.3.1
5.6.3
1
structurizr/onpremises:2025.11.094b5ffb5119c8
httpclient5@5.5.1
5.6.3
1
tchiotludo/akhq:0.28.0c2824dc2ae44
httpclient5@5.6.1
5.6.3
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
httpclient5@5.1.3
5.6.3
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
httpclient5@5.1.3
5.6.3
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
httpclient5@5.1.3
5.6.3
1
thingsboard/tb-node:3.4.1645f43b688f7
httpclient5@5.1.3
5.6.3
1
thingsboard/tb-node:3.6.0f40a542832c4
httpclient5@5.2
5.6.3
1
thingsboard/tb-postgres:latest2d17e4e36edc
httpclient5@5.4.4
5.6.3
1
traccar/traccar:6.7-alpine621c8d6d46fd
httpclient5@5.3.1
5.6.3
1
trinodb/trino:4801565e8cac299
httpclient5@5.2.1
5.6.3
1
trinodb/trino:45038c6f24ab1a4
httpclient5@5.3.1
5.6.3
1
trinodb/trino:4815b5e0a97f599
httpclient5@5.6.1
5.6.3
1
trinodb/trino:4796af989b0846d
httpclient5@5.2.1
5.6.3
1
trinodb/trino:405ee80ab5eeab2
httpclient5@5.1
5.6.3
1
vespaengine/vespa:8.526.1569b160f58211
httpclient5@5.3.1
5.6.3
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
httpclient5@5.4.3
5.6.3
1
wazuh/wazuh-indexer:4.14.3b149b30da686
httpclient5@5.4.3
5.6.3
1
yuzutech/kroki:0.17.0192b7b27c857
httpclient5@5.1.3
5.6.3
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient5@5.2.1
5.6.3
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
httpclient5@5.5
5.6.3
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
httpclient5@5.1.4
5.6.3
1
ghcr.io/axelixlabs/axelix:1.1.0449dc880bbfb
httpclient5@5.6.1
5.6.3
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
httpclient5@5.2.3
5.6.3
1
ghcr.io/comet-ml/opik/opik-backend:2.2.5950a7aa0562f5
httpclient5@5.6.1
5.6.3
1
ghcr.io/cosmo-tech/cosmotech-api:5.2.0269ee25c359b
httpclient5@5.5.2
5.6.3
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
httpclient5@5.0.3
5.6.3
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
httpclient5@5.4.4
5.6.3
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
httpclient5@5.5.2
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.