HIGH🇬🇧 English

CVE-2026-40542

CVSS 7.3v3.1pub. 2026-04-22upd. 2026-08-27

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Apache Httpclient

    APP
    Apache
    5.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-71290CRITICAL9.1ten sam produkt

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific...

CVE-2013-4366CRITICAL9.8PL ✓ten sam produkt

Apache HttpClient 4.3.x — brak weryfikacji X509HostnameVerifier (null pointer)

CVE-2025-27820HIGH7.5ten sam produkt

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management a...

CVE-2026-64607MEDIUM5.3ten sam produkt

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the con...

CVE-2020-13956MEDIUM5.3ten sam produkt

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in...