StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
httpclient5@5.0.3
5.6.3

Open the chart page →

415
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
httpclient5@5.5.1
5.6.3

Open the chart page →

1,466
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
httpclient5@5.0.3
5.6.3

Open the chart page →

866
mod-ncipfolio-org0.1.341 of 1See more

mod-ncip folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-ncip:latest8ed83674352b
httpclient5@5.2.1
5.6.3

Open the chart page →

1,103
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
httpclient5@5.5.1
5.6.3

Open the chart page →

394
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
httpclient5@5.6.1
5.6.3

Open the chart page →

1,531
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
httpclient5@5.1.3
5.6.3

Open the chart page →

34,754
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient5@5.6.1
5.6.3

Open the chart page →

4,556
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
httpclient5@5.5.2
5.6.3

Open the chart page →

1,691
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
httpclient5@5.6
5.6.3

Open the chart page →

3,199
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
httpclient5@5.2.1
5.6.3

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
httpclient5@5.5.1
5.6.3

Open the chart page →

8,541
kibanahelmforgeVerified publisher1.1.71 of 3See more

kibana helmforge 1.1.7

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
library/elasticsearch:9.5.19656a9ca03f8
httpclient5@5.6.1
5.6.3

Open the chart page →

341
openbashelm-openbasVerified publisher1.8.142 of 7See more

openbas helm-openbas 1.8.14

2 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
httpclient5@5.3.1
5.6.3
opensearchproject/opensearch:3.3.2798cf28e226a
httpclient5@5.4.4
5.6.3

Open the chart page →

25,017
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient5@5.1.3
5.6.3

Open the chart page →

37,671
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
httpclient5@5.2.1
5.6.3

Open the chart page →

1,754
daveit-at-mOfficialVerified publisher0.2.154 of 11See more

dave it-at-m 0.2.15

4 of the 11 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
httpclient5@5.5.2
5.6.3
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
httpclient5@5.5.2
5.6.3

Open the chart page →

15,089
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient5@5.3.1
5.6.3

Open the chart page →

7,268
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat56490ac14a31
httpclient5@5.5.1
5.6.3

Open the chart page →

1,595
kron-aapm-agentkron-pam-aapm-helmcharts1.2.51 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.41cc7d5be6529
httpclient5@5.4.4
5.6.3

Open the chart page →

2,707
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
httpclient5@5.2.1
5.6.3

Open the chart page →

6,490
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
httpclient5@5.6.1
5.6.3

Open the chart page →

3,818
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
httpclient5@5.2.1
5.6.3

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
httpclient5@5.2.1
5.6.3

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
httpclient5@5.2.1
5.6.3

Open the chart page →

4,599
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
httpclient5@5.6
5.6.3

Open the chart page →

3,687
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
httpclient5@5.4.2
5.6.3

Open the chart page →

1,783
dependency-tracknaj980.0.91 of 3See more

dependency-track naj98 0.0.9

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
dependencytrack/apiserver:latestf1da63ed610a
httpclient5@5.6.2
5.6.3

Open the chart page →

2,465
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
httpclient5@5.3.1
5.6.3

Open the chart page →

2,049
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpclient5@5.1.3
5.6.3

Open the chart page →

5,826
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
httpclient5@5.3.1
5.6.3

Open the chart page →

6,338
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
httpclient5@5.2.1
5.6.3

Open the chart page →

2,024
cp-cmfopenshift2.4.11 of 1See more

cp-cmf openshift 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.1f466f8649aa8
httpclient5@5.5.2
5.6.3

Open the chart page →

179
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.6.3

Open the chart page →

7,792
trinoopstty0.2.121 of 1See more

trino opstty 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
httpclient5@5.6.1
5.6.3

Open the chart page →

1,158
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
httpclient5@5.4.4
5.6.3

Open the chart page →

71,208
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
httpclient5@5.2.1
5.6.3

Open the chart page →

2,264
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
httpclient5@5.2.1
5.6.3

Open the chart page →

1,995
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient5@5.5.2
5.6.3

Open the chart page →

3,642
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
httpclient5@5.3.1
5.6.3

Open the chart page →

21,211
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
httpclient5@5.0.3
5.6.3

Open the chart page →

5,269
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
httpclient5@5.5.2
5.6.3

Open the chart page →

6,207
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
httpclient5@5.0.3
5.6.3

Open the chart page →

6,443
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
httpclient5@5.1
5.6.3

Open the chart page →

13,767
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
httpclient5@5.3.1
5.6.3

Open the chart page →

4,674
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
yuzutech/kroki:0.17.0192b7b27c857
httpclient5@5.1.3
5.6.3

Open the chart page →

8,715
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
httpclient5@5.1.3
5.6.3
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
httpclient5@5.1.3
5.6.3
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
httpclient5@5.1.3
5.6.3
thingsboard/tb-node:3.4.1645f43b688f7
httpclient5@5.1.3
5.6.3

Open the chart page →

25,394
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
httpclient5@5.5
5.6.3

Open the chart page →

7,637
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
httpclient5@5.3.1
5.6.3

Open the chart page →

2,144
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
httpclient5@5.5
5.6.3

Open the chart page →

1,527

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient5@5.3.1
5.6.3
3
airbyte/workload-launcher:2.2.0119be7bfb719
httpclient5@5.5
5.6.3
2
apache/druid:37.0.00116fb802786
httpclient5@5.5.1
5.6.3
2
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.6.3
2
epam/ai-dial-core:0.47.0:latest00fab0cf9c78
httpclient5@5.6.1
5.6.3
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
httpclient5@5.1.3
5.6.3
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
httpclient5@5.6.1
5.6.3
2
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3
2
nacos/nacos-server:latest1c191c30c8cd
httpclient5@5.5.2
5.6.3
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
httpclient5@5.4.4
5.6.3
2
ghcr.io/janssenproject/jans/casa:0.0.0-nightly3f2d14563495
httpclient5@5.5
5.6.3
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
httpclient5@5.3
5.6.3
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
httpclient5@5.0.3
5.6.3
2
2martens/configserver:latestbf1cdb80239d
httpclient5@5.3.1
5.6.3
1
2martens/timetable:latestbd1ba6ab84c9
httpclient5@5.5
5.6.3
1
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
httpclient5@5.5
5.6.3
1
airbyte/bootloader:2.2.0f71cf4e185d5
httpclient5@5.5
5.6.3
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
httpclient5@5.5
5.6.3
1
airbyte/cron:0.40.17caf4f551c546
httpclient5@5.0.3
5.6.3
1
airbyte/cron:2.2.0d97b67a1346d
httpclient5@5.5
5.6.3
1
airbyte/server:2.2.070e125498a1c
httpclient5@5.5
5.6.3
1
airbyte/worker:2.2.08060b88b29c8
httpclient5@5.5
5.6.3
1
airbyte/workload-api-server:2.2.042093cff86e9
httpclient5@5.5
5.6.3
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
httpclient5@5.3
5.6.3
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
httpclient5@5.3
5.6.3
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
httpclient5@5.3
5.6.3
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
httpclient5@5.3
5.6.3
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
httpclient5@5.3
5.6.3
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
httpclient5@5.3
5.6.3
1
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3
1
apache/druid:29.0.10cef139b6bf1
httpclient5@5.1.3
5.6.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient5@5.6.1
5.6.3
1
apache/polaris:lateste66366e783f1
httpclient5@5.6.2
5.6.3
1
athou/commafeed:6.2.0-postgresql5e388351df1a
httpclient5@5.6
5.6.3
1
atlassian/bamboo:12.1.114af4bb6c8d46
httpclient5@5.4.4
5.6.3
1
atlassian/bitbucket:10.2.705933f2b1cfd
httpclient5@5.5.2
5.6.3
1
atlassian/crowd:7.2.3c81cc7d6bc9e
httpclient5@5.5.2
5.6.3
1
atlassian/jira-software:11.3.11e5548cd4eea8
httpclient5@5.4.4
5.6.3
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
httpclient5@5.0.3
5.6.3
1
bluerange/bluerange:26.1.307c8f73b55df
httpclient5@5.4.3
5.6.3
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
httpclient5@5.4.3
5.6.3
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
httpclient5@5.2.1
5.6.3
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
httpclient5@5.2.1
5.6.3
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
httpclient5@5.2.1
5.6.3
1
conductoross/conductor:3.31.09fba127693e6
httpclient5@5.3.1
5.6.3
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
httpclient5@5.5.2
5.6.3
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
httpclient5@5.0.3
5.6.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient5@5.0.1
5.6.3
1
confluentinc/cp-schema-registry:latestf0cfd047a839
httpclient5@5.5
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.