CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64607

mediumCVSS 5.3covered by 4 sourcesfirst seen 2026-07-31
A remote, anonymous attacker can exploit a vulnerability in Apache HttpComponents to conduct a denial of service attack.

CSIRTS triage

What
A vulnerability in Apache HttpComponents allows remote anonymous attackers to conduct denial of service attacks.
Who is affected
All HTTP clients using affected HttpComponents versions are vulnerable to remote DoS.
Urgency
Medium severity; remote denial of service is exploitable by anonymous attackers.
Action
Update Apache HttpComponents to the patched version addressing CVE-2026-64607.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64607

Get an email if CVE-2026-64607 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-64607

CVE.org record

Embed the live status

CVE-2026-64607 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64607 status](https://www.csirts.com/badge/CVE-2026-64607)](https://www.csirts.com/cve/CVE-2026-64607)