Skip to content

Update dependency org.apache.httpcomponents.client5:httpclient5 to v5.6.3 [SECURITY] - #2041

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.apache.httpcomponents.client5:httpclient5 (source) 5.6.15.6.3 age confidence

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

CVE-2026-64607 / GHSA-hjcp-jmpx-g3qm

More information

Details

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported Content-Encoding header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.

This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copilot AI lite review requested due to automatic review settings August 13, 2026 19:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates the Apache HttpClient 5 dependency version in the Maven build.

Changes:

  • Bumped org.apache.httpcomponents.client5:httpclient5 from 5.5.1 to 5.6.3.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@renovate
renovate Bot force-pushed the renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability branch 15 times, most recently from 274bcb8 to 98f2757 Compare August 20, 2026 14:08
@renovate
renovate Bot force-pushed the renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability branch 13 times, most recently from 041972c to df085de Compare August 26, 2026 07:52
@renovate
renovate Bot force-pushed the renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability branch 27 times, most recently from b81fb73 to 77e89ea Compare September 7, 2026 11:12
@renovate
renovate Bot force-pushed the renovate/maven-org.apache.httpcomponents.client5-httpclient5-vulnerability branch from 77e89ea to 57cb418 Compare September 8, 2026 06:29
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant