HIGH🇵🇱 Wersja polska

CVE-2026-40542

CVSS 7.3v3.1pub. 2026-04-22upd. 2026-08-27

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Apache Httpclient

    APP
    Apache
    5.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-71290CRITICAL9.1same product

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific...

CVE-2013-4366CRITICAL9.8PL ✓same product

Apache HttpClient 4.3.x — brak weryfikacji X509HostnameVerifier (null pointer)

CVE-2025-27820HIGH7.5same product

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management a...

CVE-2026-64607MEDIUM5.3same product

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the con...

CVE-2020-13956MEDIUM5.3same product

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in...