StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
httpclient5@5.3.1
5.6.3

Open the chart page →

1,341
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
httpclient5@5.4.2
5.6.3

Open the chart page →

12,019
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
httpclient5@5.5.1
5.6.3

Open the chart page →

1,446
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
httpclient5@5.5.1
5.6.3

Open the chart page →

2,657
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
glarad/mc-service-registry:latest7b02b9e7f1ef
httpclient5@5.5.2
5.6.3

Open the chart page →

6,929
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
httpclient5@5.0.3
5.6.3

Open the chart page →

37,373
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
httpclient5@5.3.1
5.6.3

Open the chart page →

1,692
opikopikOfficialVerified publisher2.2.591 of 13See more

opik opik 2.2.59

1 of the 13 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-backend:2.2.5950a7aa0562f5
httpclient5@5.6.1
5.6.3

Open the chart page →

14,334
reportportalreportportal-ioOfficialVerified publisher26.8.122 of 15See more

reportportal reportportal-io 26.8.12

2 of the 15 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
reportportal/service-api:5.15.4bf193091525a
httpclient5@5.4.3
5.6.3
reportportal/service-authorization:5.15.16a954407b417
httpclient5@5.5.1
5.6.3

Open the chart page →

11,869
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
httpclient5@5.4.2
5.6.3

Open the chart page →

7,432
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient5@5.3
5.6.3

Open the chart page →

2,406
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
httpclient5@5.5
5.6.3

Open the chart page →

1,482
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
httpclient5@5.3.1
5.6.3

Open the chart page →

293
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
httpclient5@5.1.4
5.6.3

Open the chart page →

13,486
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
httpclient5@5.0.3
5.6.3

Open the chart page →

1,413
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
httpclient5@5.5
5.6.3

Open the chart page →

829
airbyteairbyte-v2Verified publisher2.2.06 of 10See more

airbyte airbyte-v2 2.2.0

6 of the 10 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
airbyte/bootloader:2.2.0f71cf4e185d5
httpclient5@5.5
5.6.3
airbyte/cron:2.2.0d97b67a1346d
httpclient5@5.5
5.6.3
airbyte/server:2.2.070e125498a1c
httpclient5@5.5
5.6.3
airbyte/worker:2.2.08060b88b29c8
httpclient5@5.5
5.6.3
airbyte/workload-api-server:2.2.042093cff86e9
httpclient5@5.5
5.6.3
airbyte/workload-launcher:2.2.0119be7bfb719
httpclient5@5.5
5.6.3

Open the chart page →

12,473
airbyte-data-planeairbyte-v2Verified publisher2.2.01 of 1See more

airbyte-data-plane airbyte-v2 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
airbyte/workload-launcher:2.2.0119be7bfb719
httpclient5@5.5
5.6.3

Open the chart page →

790
aktoakto0.2.03 of 7See more

akto akto 0.2.0

3 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-dashboard:latestb53a854bd7c1
httpclient5@5.3
5.6.3
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
httpclient5@5.3
5.6.3
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
httpclient5@5.3
5.6.3

Open the chart page →

13,613
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
httpclient5@5.3
5.6.3

Open the chart page →

9,321
akto-central-setupakto1.1.102 of 5See more

akto-central-setup akto 1.1.10

2 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
httpclient5@5.3
5.6.3
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2b53a854bd7c1
httpclient5@5.3
5.6.3

Open the chart page →

4,905
akto-dashboardakto0.1.71 of 1See more

akto-dashboard akto 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
httpclient5@5.3
5.6.3

Open the chart page →

1,162
akto-hybrid-redactakto1.44.42 of 5See more

akto-hybrid-redact akto 1.44.4

2 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.1_localf2e2d816ef82
httpclient5@5.3
5.6.3
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
httpclient5@5.3
5.6.3

Open the chart page →

4,777
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
httpclient5@5.3
5.6.3

Open the chart page →

2,741
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
httpclient5@5.3
5.6.3

Open the chart page →

6,486
akto-regional-setupakto1.3.13 of 9See more

akto-regional-setup akto 1.3.1

3 of the 9 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
httpclient5@5.3
5.6.3
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
httpclient5@5.3
5.6.3
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
httpclient5@5.3
5.6.3

Open the chart page →

7,603
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
httpclient5@5.3
5.6.3

Open the chart page →

1,411
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
httpclient5@5.3
5.6.3

Open the chart page →

1,490
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
httpclient5@5.3
5.6.3

Open the chart page →

1,523
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
httpclient5@5.2.3
5.6.3

Open the chart page →

28,131
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
httpclient5@5.4.4
5.6.3

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:latest536358d7b17e
httpclient5@5.4.4
5.6.3

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
httpclient5@5.1.4
5.6.3

Open the chart page →

16,975
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
httpclient5@5.4.3
5.6.3

Open the chart page →

1,816
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
httpclient5@5.2.1
5.6.3

Open the chart page →

1,215
cp-helm-chartscp-helm-charts0.6.11 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

1 of the 8 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient5@5.0.1
5.6.3

Open the chart page →

58,857
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
httpclient5@5.0.3
5.6.3

Open the chart page →

13,936
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latestf0cfd047a839
httpclient5@5.5
5.6.3

Open the chart page →

532
metabasedasmeta0.1.01 of 1See more

metabase dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.1.124f150effd484
httpclient5@5.6.2
5.6.3

Open the chart page →

804
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
httpclient5@5.0.3
5.6.3

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
httpclient5@5.0.3
5.6.3

Open the chart page →

6,915
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient5@5.3.1
5.6.3

Open the chart page →

7,268
factor-platformfactorhouseVerified publisher0.0.41 of 1See more

factor-platform factorhouse 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.414728f9fd80f
httpclient5@5.6.2
5.6.3

Open the chart page →

59
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
httpclient5@5.6.1
5.6.3

Open the chart page →

467
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.6.3

Open the chart page →

7,792
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient5@5.4.1
5.6.3

Open the chart page →

4,536
edge-caiasoftfolio-org0.1.321 of 1See more

edge-caiasoft folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/edge-caiasoft:latestc3cfa89eee2f
httpclient5@5.6.1
5.6.3

Open the chart page →

525
edge-dematicfolio-org0.1.331 of 1See more

edge-dematic folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/edge-dematic:latest48c9b1d180d4
httpclient5@5.6.1
5.6.3

Open the chart page →

525
edge-inn-reachfolio-org0.1.41 of 1See more

edge-inn-reach folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/edge-inn-reach:latestc64e4d9dd3fc
httpclient5@5.6.1
5.6.3

Open the chart page →

525
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
httpclient5@5.5.2
5.6.3

Open the chart page →

1,259

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
httpclient5@5.5.2
5.6.3
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
httpclient5@5.6.1
5.6.3
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
httpclient5@5.5
5.6.3
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
httpclient5@5.0.3
5.6.3
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
httpclient5@5.2.1
5.6.3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
httpclient5@5.1.4
5.6.3
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
httpclient5@5.5.2
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.1_localf2e2d816ef82
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
httpclient5@5.3
5.6.3
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
httpclient5@5.4.2
5.6.3
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
httpclient5@5.0.3
5.6.3
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
httpclient5@5.1.4
5.6.3
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
httpclient5@5.2.3
5.6.3
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
httpclient5@5.2.3
5.6.3
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient5@5.4.1
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.