StackRadar

CVE-2026-64607

Medium

Advisory

Published 31 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.0.1, 5.0.3, 5.1, 5.1.3+16 more5.6.3178
OSV records
GHSA-hjcp-jmpx-g3qm

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3

Open the chart page →

1,689
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
httpclient5@5.4.3
5.6.3

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3

Open the chart page →

9,397
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3

Open the chart page →

1,639
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient5@5.2.1
5.6.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-64607.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpclient5@5.0.3
5.6.3

Open the chart page →

6,016

Container images carrying it

178 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient5@5.3.1
5.6.3
3
airbyte/workload-launcher:2.2.0119be7bfb719
httpclient5@5.5
5.6.3
2
apache/druid:37.0.00116fb802786
httpclient5@5.5.1
5.6.3
2
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.6.3
2
epam/ai-dial-core:0.47.0:latest00fab0cf9c78
httpclient5@5.6.1
5.6.3
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
httpclient5@5.1.3
5.6.3
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
httpclient5@5.6.1
5.6.3
2
metabase/metabase:v0.61.1.x9491ed11c901
httpclient5@5.4.4
5.6.3
2
nacos/nacos-server:latest1c191c30c8cd
httpclient5@5.5.2
5.6.3
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
httpclient5@5.4.4
5.6.3
2
ghcr.io/janssenproject/jans/casa:0.0.0-nightly3f2d14563495
httpclient5@5.5
5.6.3
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
httpclient5@5.3
5.6.3
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
httpclient5@5.0.3
5.6.3
2
2martens/configserver:latestbf1cdb80239d
httpclient5@5.3.1
5.6.3
1
2martens/timetable:latestbd1ba6ab84c9
httpclient5@5.5
5.6.3
1
2martens/wahlrecht:latestba2c3040dab0
httpclient5@5.5
5.6.3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
httpclient5@5.5
5.6.3
1
airbyte/bootloader:2.2.0f71cf4e185d5
httpclient5@5.5
5.6.3
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
httpclient5@5.5
5.6.3
1
airbyte/cron:0.40.17caf4f551c546
httpclient5@5.0.3
5.6.3
1
airbyte/cron:2.2.0d97b67a1346d
httpclient5@5.5
5.6.3
1
airbyte/server:2.2.070e125498a1c
httpclient5@5.5
5.6.3
1
airbyte/worker:2.2.08060b88b29c8
httpclient5@5.5
5.6.3
1
airbyte/workload-api-server:2.2.042093cff86e9
httpclient5@5.5
5.6.3
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
httpclient5@5.3
5.6.3
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
httpclient5@5.3
5.6.3
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
httpclient5@5.3
5.6.3
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
httpclient5@5.3
5.6.3
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
httpclient5@5.3
5.6.3
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
httpclient5@5.3
5.6.3
1
apache/drill:1.21.11f96558fd292
httpclient5@5.1.3
5.6.3
1
apache/druid:29.0.10cef139b6bf1
httpclient5@5.1.3
5.6.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient5@5.6.1
5.6.3
1
apache/polaris:lateste66366e783f1
httpclient5@5.6.2
5.6.3
1
athou/commafeed:6.2.0-postgresql5e388351df1a
httpclient5@5.6
5.6.3
1
atlassian/bamboo:12.1.114af4bb6c8d46
httpclient5@5.4.4
5.6.3
1
atlassian/bitbucket:10.2.705933f2b1cfd
httpclient5@5.5.2
5.6.3
1
atlassian/crowd:7.2.3c81cc7d6bc9e
httpclient5@5.5.2
5.6.3
1
atlassian/jira-software:11.3.11e5548cd4eea8
httpclient5@5.4.4
5.6.3
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
httpclient5@5.0.3
5.6.3
1
bluerange/bluerange:26.1.307c8f73b55df
httpclient5@5.4.3
5.6.3
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
httpclient5@5.4.3
5.6.3
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
httpclient5@5.2.1
5.6.3
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
httpclient5@5.2.1
5.6.3
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
httpclient5@5.2.1
5.6.3
1
conductoross/conductor:3.31.09fba127693e6
httpclient5@5.3.1
5.6.3
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
httpclient5@5.5.2
5.6.3
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
httpclient5@5.0.3
5.6.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient5@5.0.1
5.6.3
1
confluentinc/cp-schema-registry:latestf0cfd047a839
httpclient5@5.5
5.6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.