Echo: org.apache.httpcomponents.client5:httpclient5: security update to 5.6.3

medium Tenable Self-Hosted Container Security Plugin ID 462254

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the
connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the
response message. Please note this defect does not affect HttpClient based on the async i/o model. This
issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2. (CVE-2026-64607)

Solution

Update the org.apache.httpcomponents.client5:httpclient5 library and its related packages to version 5.6.3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-64607

Plugin Details

Severity: Medium

ID: 462254

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-64607

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 7/31/2026

Reference Information

CVE: CVE-2026-64607