StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3

Open the chart page →

1,689
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
httpclient5@5.4.3
5.6.3

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3

Open the chart page →

9,397
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3

Open the chart page →

1,639
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient5@5.2.1
5.6.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3

Open the chart page →

6,016

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
httpclient5@5.5.2
5.6.3
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
httpclient5@5.5.2
5.6.3
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
httpclient5@5.5.2
5.6.3
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
httpclient5@5.6.1
5.6.3
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
httpclient5@5.5
5.6.3
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
httpclient5@5.0.3
5.6.3
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
httpclient5@5.2.1
5.6.3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
httpclient5@5.1.4
5.6.3
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
httpclient5@5.5.2
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.1_localf2e2d816ef82
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
httpclient5@5.3
5.6.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
httpclient5@5.3
5.6.3
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
httpclient5@5.4.2
5.6.3
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
httpclient5@5.0.3
5.6.3
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
httpclient5@5.1.4
5.6.3
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
httpclient5@5.2.3
5.6.3
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
httpclient5@5.2.3
5.6.3
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient5@5.4.1
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.