org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification

cve CVE-2026-71290 2 sources, 2 claims · Watch

Red Hat writes:
org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification the claim
Severity they disagree
CRITICAL NVD
important Red Hat
CVSS they disagree
9.1 NVD
8.1 Red Hat
Vendor
Apache Software Foundation NVD
Product
Apache HttpComponents Client NVD
CWE
CWE-295 NVD
CWE-295 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nadjacent A
Attack complexity AClow Llow L
Privileges required PRnone Nnone N
User interaction UInone Nnone N
Scope Sunchanged Uunchanged U
Confidentiality Chigh Hhigh H
Integrity Ihigh Hhigh H
Availability Anone Nnone N

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-08-11first spoke of it: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.NVD
2026-08-11first spoke of it: org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verificationRed Hat

What it is to other things

affectsapache/httpclient
NVD
made_byapache
NVD

In words only, so not counted until a person confirms one:

made_byapache_software_foundation
NVD says “Apache Software Foundation”
affectsapache_software_foundation/apache_httpcomponents_client
NVD says “Apache Software Foundation · Apache HttpComponents Client”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCyes
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD9.1
receipt
Source
NVD
Its words
9.1
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat8.1
receipt
Source
Red Hat
Its words
8.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-71290",
  "CWE": "CWE-295",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2514394",
  "bugzilla_description": "org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T20:33:56Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-71290.json",
  "severity": "important"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-71290",
  "CWE": "CWE-295",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2514394",
  "bugzilla_description": "org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T20:33:56Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-71290.json",
  "severity": "important"
}
—
CWE
cwe
NVDCWE-295
receipt
Source
NVD
Its words
CWE-295
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-295
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
Red HatCWE-295
receipt
Source
Red Hat
Its words
CWE-295
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-71290",
  "CWE": "CWE-295",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2514394",
  "bugzilla_description": "org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T20:33:56Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-71290.json",
  "severity": "important"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDApache HttpComponents Client
receipt
Source
NVD
Its words
Apache HttpComponents Client
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache HttpComponents Client
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
NVDCRITICAL
From the CVSS base score at 9.0 and above.
receipt
Source
NVD
Its words
CRITICAL
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCRITICAL
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
critical
Severity
severity
conflict
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-71290",
  "CWE": "CWE-295",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2514394",
  "bugzilla_description": "org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T20:33:56Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-71290.json",
  "severity": "important"
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache Software Foundation
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2/",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.httpcomponents.client5:httpclient5",
            "product": "Apache HttpComponents Client",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "5.6.3",
                "status": "affected",
                "version": "5.4-alpha",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E0A77896-6021-44F0-9EA9-C79EECD7A7E8",
                "versionEndExcluding": "5.6.4",
                "versionStartIncluding": "5.4",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. \n\n\nPlease note the classic version of HttpClient is not affected by this vulnerability. \n\nAffected users are recommended to upgrade to at least version 5.6.4, which fixes the issue."
      }
    ],
    "id": "CVE-2026-71290",
    "lastModified": "2026-09-24T04:17:48.873",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-71290",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-11T21:17:51.157",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Release Notes"
        ],
        "url": "https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/13/6"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification
zetlyn/cve-redhat · 2026-08-11
cvss 8.1 cvss_vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N cwe CWE-295 severity important source
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
zetlyn/cve-nvd · 2026-08-11
automatable yes cvss 9.1 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N cwe CWE-295 exploitation none product Apache HttpComponents Client severity CRITICAL status Analyzed technical_impact total vendor Apache Software Foundation source